• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to prevent DDOS using Snort?

Scheduled Pinned Locked Moved IDS/IPS
29 Posts 5 Posters 8.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jlee18
    last edited by Oct 11, 2018, 5:46 PM

    someone attacked my router last night and i want to defend it using snort i need some suggestions how to set it up properly to prevent ddos.

    1 Reply Last reply Reply Quote 0
    • D
      Derelict LAYER 8 Netgate
      last edited by Oct 11, 2018, 5:51 PM

      Attacked how?

      Snort can't defend against what is usually called a DDoS (flooding your link with packets from distributed sources) because by the time it arrives it's too late to do anything about it.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      J 1 Reply Last reply Oct 11, 2018, 5:54 PM Reply Quote 0
      • J
        jlee18 @Derelict
        last edited by Oct 11, 2018, 5:54 PM

        @derelict said in How to prevent DDOS using Snort?:

        Attacked how?

        Snort can't defend against what is usually called a DDoS (flooding your link with packets from distributed sources) because by the time it arrives it's too late to do anything about it.

        do you have any suggestion how i can prevent any attacks sir?

        1 Reply Last reply Reply Quote 0
        • D
          Derelict LAYER 8 Netgate
          last edited by Oct 11, 2018, 5:56 PM

          If it is a true DDoS there is nothing you can do but go upstream and have them try to block it.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • J
            jlee18
            last edited by Oct 11, 2018, 6:17 PM

            this PFBlocker and snort are useless?

            1 Reply Last reply Reply Quote 0
            • D
              Derelict LAYER 8 Netgate
              last edited by Oct 11, 2018, 6:20 PM

              To a DDoS consisting of traffic overwhelming your interface yes, they are useless.

              Look. The traffic is already there. Your "pipe" is already full. Any action taken on your side of the interface cannot change that. All it can do is drop it which is the default behavior of the firewall.

              You might get some relief by disabling logging of dropped packets in Status > System Logs, Settings, Log firewall default blocks but that won't do anything to stop the traffic - just might reduce the load on the firewall in processing it.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz Oct 11, 2018, 6:30 PM Oct 11, 2018, 6:25 PM

                When you say attacked - this means what exactly to you?? You saw some blocked hits in your firewall? How do you know your router was attacked last night?

                I could say my router gets attacked every few seconds - if you look in your firewall log and think that every unsolicited hit is an "attack" ;)

                They like to attack the common ports, 23, 22, 3389, 80, 1433 - loads and loads of attacks ;) Or what normal people would call noise.. The internet is FULL of it...

                Look at all the noise ;)
                0_1539282642435_noise.png

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • J
                  jlee18
                  last edited by Oct 11, 2018, 7:45 PM

                  I saw many TCP connections/IP coming to my WAN public IP port 8080 9pm to 11:30 pm 11:35 pm the internet became normal again. from 30-40 ping my ping goes up to 1000 2000 3000 we are dead last night. my ntopng is not working last night because of the new updates.

                  I want to know how can i prevent those incoming flood to my WAN public IP.

                  1 Reply Last reply Reply Quote 0
                  • D
                    Derelict LAYER 8 Netgate
                    last edited by Oct 11, 2018, 7:48 PM

                    Do you have rules on WAN passing traffic to that port? Do you know what is on 8080 on WAN?

                    You are getting bad information because you called it a DDoS.

                    The very first thing I asked was "Attacked how?"

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    J 1 Reply Last reply Oct 11, 2018, 8:06 PM Reply Quote 0
                    • N
                      NogBadTheBad
                      last edited by NogBadTheBad Oct 11, 2018, 7:53 PM Oct 11, 2018, 7:53 PM

                      Just to give us an idea post a screenshot of the bottom of Status -> System Logs -> Firewall -> Summary View.

                      Here's mine I only have 3000 ish drops in total.

                      0_1539287574336_Screenshot 2018-10-11 at 20.51.45.png

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      1 Reply Last reply Reply Quote 0
                      • J
                        jlee18
                        last edited by Oct 11, 2018, 8:02 PM

                        0_1539288089617_f8472c05-294f-465b-af83-ad03b3cf2e8e-image.png

                        0_1539288150598_97423e2a-68d7-4d18-a557-2ee40776362f-image.png

                        1 Reply Last reply Reply Quote 0
                        • J
                          jlee18 @Derelict
                          last edited by Oct 11, 2018, 8:06 PM

                          @derelict said in How to prevent DDOS using Snort?:

                          Do you have rules on WAN passing traffic to that port? Do you know what is on 8080 on WAN?

                          You are getting bad information because you called it a DDoS.

                          The very first thing I asked was "Attacked how?"

                          what should i do sir?

                          1 Reply Last reply Reply Quote 0
                          • D
                            Derelict LAYER 8 Netgate
                            last edited by Oct 11, 2018, 8:06 PM

                            Please answer the questions asked for starters.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            J 1 Reply Last reply Oct 11, 2018, 8:10 PM Reply Quote 0
                            • N
                              NogBadTheBad
                              last edited by NogBadTheBad Oct 11, 2018, 8:08 PM Oct 11, 2018, 8:06 PM

                              no 8080 there, have you cleared the firewall logs ?

                              But as Derelict mentioned in his first post if it is a DDoS there isn't much you can do apart from talking to your ISP.

                              Andy

                              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                              1 Reply Last reply Reply Quote 0
                              • J
                                jlee18 @Derelict
                                last edited by Oct 11, 2018, 8:10 PM

                                @derelict i dont have a RULES for that port. im using the default rules.

                                1 Reply Last reply Reply Quote 0
                                • D
                                  Derelict LAYER 8 Netgate
                                  last edited by Oct 11, 2018, 8:33 PM

                                  Then the connections would have been being blocked and there's not much you can do but talk to upstream to stop it.

                                  Hard to imagine someone sending enough TCP SYNs to a blocked port to be a problem though.

                                  Chattanooga, Tennessee, USA
                                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                  1 Reply Last reply Reply Quote 0
                                  • J
                                    jlee18
                                    last edited by Oct 11, 2018, 9:15 PM

                                    @derelict said in How to prevent DDOS using Snort?:

                                    you can do but talk to upstream to stop it

                                    what do you mean by upstream? "you can do but talk to upstream to stop it"
                                    Internet provider?

                                    1 Reply Last reply Reply Quote 0
                                    • D
                                      Derelict LAYER 8 Netgate
                                      last edited by Oct 11, 2018, 9:15 PM

                                      Yes.

                                      Chattanooga, Tennessee, USA
                                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                      J 1 Reply Last reply Oct 11, 2018, 10:52 PM Reply Quote 0
                                      • J
                                        jlee18 @Derelict
                                        last edited by Oct 11, 2018, 10:52 PM

                                        this PFBlockerNG and Snort are useless ? can i just close my WAN ports?

                                        Thank you So much.

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          Derelict LAYER 8 Netgate
                                          last edited by Oct 11, 2018, 10:53 PM

                                          You said they WERE closed.

                                          Post your WAN rules.

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          1 Reply Last reply Reply Quote 0
                                          20 out of 29
                                          • First post
                                            20/29
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received