Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to prevent DDOS using Snort?

    Scheduled Pinned Locked Moved IDS/IPS
    29 Posts 5 Posters 8.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz

      When you say attacked - this means what exactly to you?? You saw some blocked hits in your firewall? How do you know your router was attacked last night?

      I could say my router gets attacked every few seconds - if you look in your firewall log and think that every unsolicited hit is an "attack" ;)

      They like to attack the common ports, 23, 22, 3389, 80, 1433 - loads and loads of attacks ;) Or what normal people would call noise.. The internet is FULL of it...

      Look at all the noise ;)
      0_1539282642435_noise.png

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • J
        jlee18
        last edited by

        I saw many TCP connections/IP coming to my WAN public IP port 8080 9pm to 11:30 pm 11:35 pm the internet became normal again. from 30-40 ping my ping goes up to 1000 2000 3000 we are dead last night. my ntopng is not working last night because of the new updates.

        I want to know how can i prevent those incoming flood to my WAN public IP.

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          Do you have rules on WAN passing traffic to that port? Do you know what is on 8080 on WAN?

          You are getting bad information because you called it a DDoS.

          The very first thing I asked was "Attacked how?"

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          J 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by NogBadTheBad

            Just to give us an idea post a screenshot of the bottom of Status -> System Logs -> Firewall -> Summary View.

            Here's mine I only have 3000 ish drops in total.

            0_1539287574336_Screenshot 2018-10-11 at 20.51.45.png

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • J
              jlee18
              last edited by

              0_1539288089617_f8472c05-294f-465b-af83-ad03b3cf2e8e-image.png

              0_1539288150598_97423e2a-68d7-4d18-a557-2ee40776362f-image.png

              1 Reply Last reply Reply Quote 0
              • J
                jlee18 @Derelict
                last edited by

                @derelict said in How to prevent DDOS using Snort?:

                Do you have rules on WAN passing traffic to that port? Do you know what is on 8080 on WAN?

                You are getting bad information because you called it a DDoS.

                The very first thing I asked was "Attacked how?"

                what should i do sir?

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  Please answer the questions asked for starters.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  J 1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad
                    last edited by NogBadTheBad

                    no 8080 there, have you cleared the firewall logs ?

                    But as Derelict mentioned in his first post if it is a DDoS there isn't much you can do apart from talking to your ISP.

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    1 Reply Last reply Reply Quote 0
                    • J
                      jlee18 @Derelict
                      last edited by

                      @derelict i dont have a RULES for that port. im using the default rules.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Then the connections would have been being blocked and there's not much you can do but talk to upstream to stop it.

                        Hard to imagine someone sending enough TCP SYNs to a blocked port to be a problem though.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • J
                          jlee18
                          last edited by

                          @derelict said in How to prevent DDOS using Snort?:

                          you can do but talk to upstream to stop it

                          what do you mean by upstream? "you can do but talk to upstream to stop it"
                          Internet provider?

                          1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate
                            last edited by

                            Yes.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            J 1 Reply Last reply Reply Quote 0
                            • J
                              jlee18 @Derelict
                              last edited by

                              this PFBlockerNG and Snort are useless ? can i just close my WAN ports?

                              Thank you So much.

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                You said they WERE closed.

                                Post your WAN rules.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by johnpoz

                                  Unless you created a port forward, or running openvpn or something where the wizard would all traffic on your wan to port vpn listen on ALL unsolicited traffic to your wan is dropped/blocked out of the box.

                                  Please post your wan rules as asked, and actually state why you feel you were attacked? A couple hundred hits? Is that even your WAN.. the 5353 and 1900 are most likely broadcast traffic from your lan side.. Or its BS noise from your ISP layer 2 on your wan.

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • J
                                    jlee18
                                    last edited by

                                    0_1539350384030_8fffb162-ccbe-4355-9edf-7803559b84b9-image.png

                                    0_1539350399837_46af302c-90ab-4476-a473-4b19e397d31a-image.png

                                    1 Reply Last reply Reply Quote 0
                                    • NogBadTheBadN
                                      NogBadTheBad
                                      last edited by

                                      Any floating rules ?

                                      Andy

                                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                      1 Reply Last reply Reply Quote 0
                                      • J
                                        jlee18
                                        last edited by

                                        0_1539350616775_0e5eddd1-b250-4aed-97e4-37a16aa47e02-image.png

                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by johnpoz

                                          The rules on your wan are pointless!!! All interfaces have default deny on them.. Its pointless for those rules unless you have turned off default logging and just want to log those ports and pings.

                                          And again where is this attack?, I see nothing in your logs but some very LOW level amount of noise...

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          J 1 Reply Last reply Reply Quote 0
                                          • J
                                            jlee18 @johnpoz
                                            last edited by

                                            @johnpoz said in How to prevent DDOS using Snort?:

                                            The rules on your wan are pointless!!! All interfaces have default deny on them.. Its pointless for those rules unless you have turned off default logging and just want to log those ports and pings.

                                            what should i do sir ? delete the port 80 and 443 rules? to avoid incoming SYN flood to my WAN IP?

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.