Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Blocking Google/Gmail

    Scheduled Pinned Locked Moved IDS/IPS
    12 Posts 3 Posters 3.8k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O Offline
      Overcon
      last edited by

      Hi All,

      I could use some help. I just enabled Suricata on my pFsense box after running it on just logging and trying to figure out and exclude false positives. But now that I have it actually blocking stuff, one of the things it is blocking and I can't find out what rule is Google.

      So when I try and do a search in my browsers which have Google as the search engine, I just get:

      Unable to connect

      An error occurred during a connection to www.google.com.

      The site could be temporarily unavailable or too busy. Try again in a few moments.
      If you are unable to load any pages, check your computer’s network connection.
      If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the Web.
      

      I am new to this and not sure how to find the rule blocking this traffic. Could anyone help me find which rule so I can disable it?

      Thanks!

      S 1 Reply Last reply Reply Quote 0
      • S Offline
        SteveITS Rebel Alliance @Overcon
        last edited by

        @overcon Look on the Alerts tab for alerts from your LAN IP at the time you are trying to connect to that site. Are you using Legacy or Inline mode?

        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
        Upvote 👍 helpful posts!

        O 1 Reply Last reply Reply Quote 0
        • O Offline
          Overcon @SteveITS
          last edited by

          @steveits Hi Steve. I am using the Legacy mode. I am looking at the log from pfsense Alerts tab, I am not seeing a time matching when I try and refresh the browser search. The closest I have are these:

          04/17/2022-01:37:25.296133 [] [1:2025275:4] ET INFO Windows OS Submitting USB Metadata to Microsoft [] [Classification: Misc activity] [Priority: 3] {TCP} 172.16.1.151:50983 -> 52.188.50.245:80
          04/17/2022-01:41:09.123967 [] [1:2210042:2] SURICATA STREAM TIMEWAIT ACK with wrong seq [] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 104.248.148.95:53736 -> 172.16.1.240:443

          S 1 Reply Last reply Reply Quote 0
          • S Offline
            SteveITS Rebel Alliance @Overcon
            last edited by

            @overcon Which of those 172.16.1.x IPs is your PC? The second one looks like a connection inbound to a web server on your LAN...? 52.188.50.245 looks like a Microsoft IP.

            Overall, if the IP of www.google.com isn't in the Blocks tab then it isn't currently blocked, and if it isn't in the Alerts tab log then it wasn't Suricata doing the blocking.

            re: Stream, we disable ALL stream-events.rules for Suricata because it seems to trigger lots of false positives.

            Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
            Upvote 👍 helpful posts!

            O 1 Reply Last reply Reply Quote 0
            • O Offline
              Overcon @SteveITS
              last edited by

              @steveits Neither of those IP's are my desktop. My IP is 172.16.1.24 and I am not seeing my IP in any of the Alerts. 172.16.1.240 is a webserver.

              It is definitely something in Suricata (or something associated with something it is blocking), as everything was working until I enabled it. I was thinking it might be interfering with my Pihole DNS servers, but I don't see their IPs showing up either.

              One odd thing is, I can ping google.com and I can check my email from Gmail using my mail client. But if I try and do a search with google.com or try and open Gmail using a browser it gets rejected. So maybe it isn't directly blocking Google, but it is impacting something that is causing issues with using it to search.

              O 1 Reply Last reply Reply Quote 0
              • O Offline
                Overcon @Overcon
                last edited by

                Here is everything it has dropped so far, I don't know if this would help. I did disable all the Stream-events.rules as you mentioned.

                Screenshot 2022-04-16 042630.png

                O 1 Reply Last reply Reply Quote 0
                • O Offline
                  Overcon @Overcon
                  last edited by

                  @steveits said in Suricata Blocking Google/Gmail:

                  stream-events.rules

                  I cleared all the blocks out and let it run to see if disabling the stream-events was the issue. I also noticed a lot of theseDNS queries in the Alerts, so I suppressed them (they were coming from the pi-hole servers). That is my pi-hole DNS server, so that could have been impacting web requests for google.com

                  04/16/2022-21:42:34.986693 [] [1:2027865:4] ET INFO Observed DNS Query to .cloud TLD [] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 172.16.1.7:57109 -> 95.100.175.66:53

                  1 Reply Last reply Reply Quote 0
                  • Cool_CoronaC Offline
                    Cool_Corona
                    last edited by

                    Suricata blocks Google.com from time to time.... search doesnt work in Firefox or google.

                    Turn to google.ch and it works fine.

                    It fuc**ing annoying.

                    O 1 Reply Last reply Reply Quote 0
                    • O Offline
                      Overcon @Cool_Corona
                      last edited by

                      @cool_corona Are you saying this just happens at random? God, I hope not.

                      Cool_CoronaC 1 Reply Last reply Reply Quote 0
                      • Cool_CoronaC Offline
                        Cool_Corona @Overcon
                        last edited by

                        @overcon It does. It works when you release the blocks and after some time it stops working and there is no way to log whats happening since google has a gazilion ip's....

                        S 1 Reply Last reply Reply Quote 0
                        • S Offline
                          SteveITS Rebel Alliance @Cool_Corona
                          last edited by

                          @cool_corona They do, but the LAN IP is in the Alerts tab along with the rule triggering it.

                          FWIW none of our clients have issues with google.com.

                          Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                          When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                          Upvote 👍 helpful posts!

                          Cool_CoronaC 1 Reply Last reply Reply Quote 0
                          • Cool_CoronaC Offline
                            Cool_Corona @SteveITS
                            last edited by

                            @steveits Yeah but its running in a loaded datacenter with a shitload of terminalservers accessing all kinds of sites.

                            You cant keep up and even if you witelist it, it blocks.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.