Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What is the biggest attack in GBPS you stopped

    Scheduled Pinned Locked Moved General pfSense Questions
    737 Posts 33 Posters 817.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      Supermule Banned
      last edited by

      Just got home from a nice dinner with friends and its 3.39AM here  :D

      Going to bed and will have a look during the day tomorrow. (saturday).

      @firewalluser:

      Got your XML file, I'll compare that to mine and any other's which get pm'ed and I'll try to build a table to show the differences and the common elements to hopefully make it easier to solve.

      I'm still curious to see if my home fw running pfsense 2.2.2. can be taken out so if you wanted to do a quick test, my ip is 2.101.3.83. I havent had chance to setup Skype yet as I've still got to get my mail server up and running and I dont allow ping so its not something that needs to be in the test. I've got VM recording the dashboard, pfinfo and system activity plus I'm also using a packet capture (full unlimited on the wan) so I can see whats going on. If the system falls down the ISP will automatically assign a new ip address so for the moment the 2.101.3.83 is mine to play with for now.

      Drop me a PM to say when you have done, I'll PM back to let you know if I detect any problems here or not either way.

      Edit.

      I had PM'ed the above so something got screwy with the forum comms for it to appear here but also explains my post here https://forum.pfsense.org/index.php?topic=94573.0 which is weird as I can access the forum via a free vpn no problem but can no longer access it direct, unless Supermules XML backup triggered a snort alert which is now blocking that machine - will have to check in a moment.

      Anyway have you run the script yet against my ip address? I'm still on that IP address and nothing appears to have happened if you have, so let us know Supermule if you have run the script or not.

      Much obliged.

      1 Reply Last reply Reply Quote 0
      • S Offline
        Supermule Banned
        last edited by

        Anyone care to explain this??

        Youtube Video

        2 first attacks is causing packetloss.

        Removing blocked hosts in Snort and it makes the damn thing survive 3 next attacks no problems.

        No packetloss and no CPU hits 100%.

        What does removing the snort blocked hosts exactly do to pfsense??

        Wonder if some setting is over time, resetting something because hours later its back to losing packets until I remove the blocked hosts again.

        1 Reply Last reply Reply Quote 0
        • H Offline
          Harvy66
          last edited by

          I think snort is blocking and has to inspect every connection before letting it through. Like an extra firewall, but much less efficient. Anything to reduce the work snort has to do will speed things up. Sounds like snort is single threaded in some way. Probably a similar issue with why NAT crumbles when you enabled port forwarding?

          1 Reply Last reply Reply Quote 0
          • M Offline
            mer
            last edited by

            How about dumping snort rules and then a pfctl -s rules on the pfsense box?  It's been a while since I've looked/used snort, but I would think it's looking at packets, but shouldn't be blocking pfsense until a rule match.  Then I could see Snort putting an IP address into a table and triggering PF rules based on the table.  Removing the blocked hosts from Snort likely would flush a PF table and all associated states.

            Again, this is speculation, not based on looking at a Snort/pfSense integration.

            1 Reply Last reply Reply Quote 0
            • H Offline
              Harvy66
              last edited by

              @mer:

              It's been a while since I've looked/used snort, but I would think it's looking at packets, but shouldn't be blocking pfsense until a rule match.

              If it doesn't block every packet, there is a chance a packet may get through before blocking. It could inspect packets asynchronously, then signal PF to kill a connection if it sees a "bad" packet after the fact, but most everything I see about snort is it can make your bandwidth lower. If it affects your bandwidth, then it must be acting as a middleman in some way that all packets must go through it. You also runt he issue if packets are coming in faster than snort can process them, then snort can't see every packet.

              1 Reply Last reply Reply Quote 0
              • dennypageD Offline
                dennypage
                last edited by

                Snort is an IDS rather than an IPS (which limits its usefulness). It gets a copy of the packet, and is not in the data path. When snort decides to block something, it performs the block by adding a pf rule. Look for the snort2c table.

                @Harvy66:

                I think snort is blocking and has to inspect every connection before letting it through.

                1 Reply Last reply Reply Quote 0
                • H Offline
                  Harvy66
                  last edited by

                  The only time I've ever used snort was as a passive sniffer on a mirrored port, so I was unsure how it worked when on the firewall. I assume rules inserted by snort must happen before the past path of checking if a connection already exists, and maybe this is why snort is some times associated with reduced performance.

                  1 Reply Last reply Reply Quote 0
                  • bmeeksB Offline
                    bmeeks
                    last edited by

                    Snort blocks by inserting the target IP address in pfSense pre-defined pf table called "snort2c".  That table is created during the pfSense boot process and always exists whether the Snort package is installed or not.  The table is rather high up in the chain, so it is one of the first tables (rules) a packet will see.  It's not the very first, but it does come before any other user-supplied rules.

                    The blocking module of Snort is a binary patch integrated into the Snort source code as an output plugin.  The plugin takes every Snort alert and checks the IP addresses against any Pass List (do not block list of IPs).  If there is no match to a Pass List IP, the IP is then inserted into the snort2c table using FreeBSD system calls.

                    If the "clear states" option is enabled within the Snort GUI, then the aforementioned blocking plugin will also do a FreeBSD system call to clear all states in the packet filter associated with the IP that was blocked.

                    Bill

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      Supermule Banned
                      last edited by

                      What process does it call when clearing states Bill??

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        tim.mcmanus
                        last edited by

                        C'mon.

                        Troubleshoot FreeBSD first.

                        Why is that so difficult?

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          Supermule Banned
                          last edited by

                          Its not Tim :D

                          I just want to know why it behaves like that. Currently bombing Anthonys provided IP. Hope he is stilla alive :D

                          1 Reply Last reply Reply Quote 0
                          • T Offline
                            tim.mcmanus
                            last edited by

                            It's an absolute waste of time to do anything with snort.  It's built on top of pfSense, which in turn is built on top of FreeBSD.

                            When you troubleshoot a web server, you usually start with trying to ping the server, check to see if the port is open, and then look at the applications built on top of it.  Why on God's green earth would you even look at snort?

                            If you want to resolve the issue, if you truly want to resolve the issue, eliminate the mast basic layers before you go up to the applications.  If' stopped engaging in this ruse because of the distractions.

                            I can almost guarantee that the issue is with the FreeBSD networking drivers.  I haven't seen a thread created on their forums to address or resolve the issue.  There's no more point to this thread other than being a distraction from methodically trying to identify the root cause.

                            1 Reply Last reply Reply Quote 0
                            • T Offline
                              torontob
                              last edited by

                              From those of you who are testing with Supermule, may we please have a quick update of what is happening now and what stage the testing is? And what is your current standing in regards to this issue? (e.g. will it bring the world down or not?)

                              I have lost tract since page 20 of the thread…

                              Thanks for all the hard work everyone!

                              1 Reply Last reply Reply Quote 0
                              • D Offline
                                doktornotor Banned
                                last edited by

                                @torontob:

                                may we please have a quick update of what is happening now and what stage the testing is?

                                Enough videos produced to run a dedicated YT channel for clueless nerds…

                                @torontob:

                                And what is your current standing in regards to this issue? (e.g. will it bring the world down or not?)

                                Yeah, we are all doomed.

                                1 Reply Last reply Reply Quote 0
                                • S Offline
                                  Supermule Banned
                                  last edited by

                                  Apparently not if you migrate to OPNsense…

                                  I hate the GUI but it has no issues despite beeing a fork of pfsense.

                                  http://youtu.be/98I7-UHvkPQ

                                  Even with the stage table full it keeps routing and reply. Almost zero packetloss.

                                  1 Reply Last reply Reply Quote 0
                                  • H Offline
                                    Harvy66
                                    last edited by

                                    I noticed the first test had about 30Mb in the first test and only 9Mb on the second, after you made the change for adaptive scaling. What this a DDOS syn attack or just a normal one?

                                    1 Reply Last reply Reply Quote 0
                                    • S Offline
                                      Supermule Banned
                                      last edited by

                                      DDoS.

                                      1 Reply Last reply Reply Quote 0
                                      • D Offline
                                        doktornotor Banned
                                        last edited by

                                        @Supermule:

                                        Apparently not if you migrate to OPNsense…

                                        Excellent. So, now this thread finally can be closed…

                                        1 Reply Last reply Reply Quote 0
                                        • F Offline
                                          firewalluser
                                          last edited by

                                          @doktornotor:

                                          @Supermule:

                                          Apparently not if you migrate to OPNsense…

                                          Excellent. So, now this thread finally can be closed…

                                          It doesnt help existing users of pfsense who dont want to waste time jumping ship to yet another product though.

                                          I personally would like to get to the bottom of it otherwise why even have a firewall at all then other than it helps bad actors who might be in play in a variety of ways including misleading people on threads in security forums?

                                          All or nothing.

                                          Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

                                          Asch Conformity, mainly the blind leading the blind.

                                          1 Reply Last reply Reply Quote 0
                                          • A Offline
                                            almabes
                                            last edited by

                                            Status update:

                                            I am at a point where I need help.  I am not a BSD or UNIX guru.  I need help getting pf configured with a NAT behind it.  I also have DTrace working, but need guidance with what to run to get it to capture useful data during an attack.

                                            We tested base FreeBSD 10.1-RELEASE. No pf, no NAT, just open to the wild internet.  Supermule's attacks would overwhelm my available bandwidth and the box would be unreachable.  The instant they stopped, the box was back.

                                            Then I tried to configure pf and screwed myself.  I don't have console access to the bare metal FreeBSD box, while sitting on my couch.  I'll fix it when I'm in the office today.

                                            After screwing myself, I had yard work to get done before the rains that saturated Texas attempted to do the same to Georgia and deliver a repaired laptop to the owner of a barbecue restaurant.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.