Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Logs from a printer trying to communicate with lots of IP addresses

    IDS/IPS
    3
    4
    363
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Sal
      last edited by

      Hi guys,

      I am gettings a lot of logs on Snort from a printer on the network. I tried to search, but I can't understand why this printer is trying to communicate a lot of IP addresses inside the network ( even people that don't use it ). Has any of you encountered this type of logs:
      Sport 80 120:19 (http_inspect) MULTIPLE CONTENT LENGTH IN HTTP RESPONSE

      Note: This printer is shared through windows print management and very few are people using it.

      NollipfSenseN bmeeksB 2 Replies Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @Sal
        last edited by

        @Sal I would guess it's your Windows print management and not the actual printer...you can unplug it and only plug when you need it. The log entry could be router gossip!

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 1
        • bmeeksB
          bmeeks @Sal
          last edited by bmeeks

          @Sal said in Logs from a printer trying to communicate with lots of IP addresses:

          Hi guys,

          I am gettings a lot of logs on Snort from a printer on the network. I tried to search, but I can't understand why this printer is trying to communicate a lot of IP addresses inside the network ( even people that don't use it ). Has any of you encountered this type of logs:
          Sport 80 120:19 (http_inspect) MULTIPLE CONTENT LENGTH IN HTTP RESPONSE

          Note: This printer is shared through windows print management and very few are people using it.

          Many of the HTTP_INSPECT rules are chatty and, in my humble opinion, close to being worthless in today's modern networks. There are so many devices and software applications that "violate" some sentence or paragraph of an RFC someplace and thus will trigger these HTTP_INSPECT rules. Rarely is the event actually malicious these days.

          So I would be fully comfortable disabling that rule, or at the very least suppressing it for the address of your printer and the Windows server that is hosting it.

          1 Reply Last reply Reply Quote 1
          • S
            Sal
            last edited by

            Thank you so much guys for your reply. I will go ahead a disable the rule.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.