• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort not capturing any events from internal NICS lan's

Scheduled Pinned Locked Moved pfSense Packages
4 Posts 2 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tbaror
    last edited by Feb 27, 2013, 10:51 AM

    Hello All,

    I have SNORT package installed2.9.2.3 pkg v. 2.5.4along with SQUID3.1.20 pkg 2.0.6 and NTOP```
    5.0.1 v2.3

    Snort configured to listen on the Internal LAN, since a while i don't see alert that produce on related Bittornet or all kind of HTTP malwares , i know that they happen since we caught few users by mistake.
    Also i did test myself with bittornet and didn't had any alert, its was working before .
    My question is is it possible that its stooped alerting on internal interface HTTP related to the fact SQUID is on transparent mode and operate on Internal LAN or NTOP that also listen to internal LAN?
    If yes how is it possible to make it coexist together by keeping transparent mode and still getting alerts from SNORT on such events
    
    Please advice
    Thanks
    1 Reply Last reply Reply Quote 0
    • T
      tbaror
      last edited by Mar 2, 2013, 3:44 PM

      anyone????

      1 Reply Last reply Reply Quote 0
      • B
        bmeeks
        last edited by Mar 2, 2013, 8:50 PM

        It is possible that the default $HOME_NET setting and whitelist association may be "swallowing" the alerts.  If you have the Squid box with an IP that is within your $HOME_NET IP block, then it would get automatically added to the whitelisting file and not generate alerts.  Some changes were made recently in the code sections that auto-generate the $HOME_NET values so that then entire LAN subnet gets added.  I think that $HOME_NET is also the "default" whitelisted network if you do not explicitly set a whitelist.

        Bill

        1 Reply Last reply Reply Quote 0
        • T
          tbaror
          last edited by Mar 10, 2013, 5:37 AM Mar 9, 2013, 1:22 PM

          Hi,
          Just found out what was wrong , since the HTTP is routed to port 3128 with SQUID i had to fill out Define variable HTTP_PORTS 80 and 3128
          now i have all alerts showing as used to

          Thanks

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received