<div dir="ltr">Did you have any success with libnet for rejects? <div>I've been trying to get it working and the results haven't been promising. Occasionally the connection will break on a reject rule but never fast enough. </div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Mar 27, 2015 at 11:21 AM, Rovnov Pavel <span dir="ltr"><<a href="mailto:provnov@solidex.by" target="_blank">provnov@solidex.by</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Victor,<br>
<br>
Thanks a lot for information!<br>
<span class="HOEnZb"><font color="#888888"><br>
Pavel<br>
</font></span><span class="im HOEnZb"><br>
-----Original Message-----<br>
From: <a href="mailto:oisf-users-bounces@lists.openinfosecfoundation.org">oisf-users-bounces@lists.openinfosecfoundation.org</a><br>
[mailto:<a href="mailto:oisf-users-bounces@lists.openinfosecfoundation.org">oisf-users-bounces@lists.openinfosecfoundation.org</a>] On Behalf Of<br>
</span><div class="HOEnZb"><div class="h5">Victor Julien<br>
Sent: Friday, March 27, 2015 1:50 PM<br>
To: <a href="mailto:oisf-users@lists.openinfosecfoundation.org">oisf-users@lists.openinfosecfoundation.org</a><br>
Subject: Re: [Oisf-users] Suricata - Reject in one-arm IPS/IDS mode<br>
<br>
-----BEGIN PGP SIGNED MESSAGE-----<br>
Hash: SHA1<br>
<br>
On 03/23/2015 08:09 PM, Rovnov Pavel wrote:<br>
> Hello Coop, Anthony,<br>
><br>
> I don't control neither users nor web servers. So I can't instruct<br>
> users to use proxy or run all web applications through reverse-proxy.<br>
><br>
> Inline mode is not acceptable in my scenario (let me say the guy who<br>
> owns infrastructure doesn't allow me to be inline).<br>
><br>
> What I can is to use mirrored traffic to do my analysis. So the<br>
> question remains the same:<br>
><br>
> 1)    Can I use reject when out-of-band?<br>
<br>
Yeah.<br>
<br>
> 2)    How can I specify interface to send rejects from? I can't use<br>
> 2-way SPAN port on my switch.<br>
<br>
Not sure here. I think you'd need another nic thats on your switch. We<br>
use libnet, not sure how it selects the nic to use. Might use the nic<br>
that has a valid route to the destination? Think you'll need to<br>
experiment here.<br>
<br>
Cheers,<br>
Victor<br>
<br>
<br>
><br>
> Thanks!<br>
><br>
> -----Original Message----- From: Cooper F. Nelson<br>
> [mailto:<a href="mailto:cnelson@ucsd.edu">cnelson@ucsd.edu</a>] Sent: Monday, March 23, 2015 9:59 PM To:<br>
> Rodgers, Anthony (DTMB); Rovnov Pavel;<br>
> <a href="mailto:oisf-users@lists.openinfosecfoundation.org">oisf-users@lists.openinfosecfoundation.org</a> Subject: Re:<br>
> [Oisf-users] Suricata - Reject in one-arm IPS/IDS mode<br>
><br>
> +1 to using a web proxy.  Squid is free.<br>
><br>
> You can even run suricata inline on a squid proxy and create a robust,<br>
<br>
> next-generation proxy-firewall with Layer-7 intrusion<br>
> detection/prevention.<br>
><br>
> -Coop<br>
><br>
> On 3/23/2015 9:17 AM, Rodgers, Anthony (DTMB) wrote:<br>
>> Why not use a web proxy like squid for this?<br>
><br>
><br>
><br>
>> --<br>
><br>
>> Anthony Rodgers<br>
><br>
>> Security Analyst<br>
><br>
>> Michigan Security Operations Center (MiSOC)<br>
><br>
>> DTMB, Michigan Cyber Security<br>
><br>
><br>
> _______________________________________________ Suricata IDS Users<br>
> mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org">oisf-users@openinfosecfoundation.org</a> Site:<br>
> <a href="http://suricata-ids.org" target="_blank">http://suricata-ids.org</a> | Support:<br>
> <a href="http://suricata-ids.org/support/" target="_blank">http://suricata-ids.org/support/</a> List:<br>
> <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
><br>
><br>
Training now available: <a href="http://suricata-ids.org/training/" target="_blank">http://suricata-ids.org/training/</a><br>
><br>
<br>
- --<br>
- ---------------------------------------------<br>
Victor Julien<br>
<a href="http://www.inliniac.net/" target="_blank">http://www.inliniac.net/</a><br>
PGP: <a href="http://www.inliniac.net/victorjulien.asc" target="_blank">http://www.inliniac.net/victorjulien.asc</a><br>
- ---------------------------------------------<br>
<br>
-----BEGIN PGP SIGNATURE-----<br>
Version: GnuPG v1<br>
<br>
iQEcBAEBAgAGBQJVFTXIAAoJEMH0leOSaFa0mO8H/05kirfk52HYTIOwVmqFytqG<br>
XseeP3BYaLPL6W/f9/+XCU+gqpZn+BbaBG3znot1pXKeEAuNrVzjrT228ASpbIsV<br>
6ymTBuyOwgTXYvofW47sCEpRlcc5fukAqWYTxmmrLQJpfMMjUfq9v74IqJBeL0x2<br>
Cu9VHICY9RxDyYUBYSakGX4DeVmTIYNdEYw5qe0jdw+2Ikv4v27ef1Sm5cpknKLG<br>
AWGeflIEiQWWuMkRxw1HMMdbc3mmniA3tbzuktvp88o6vsKBlgoa45SsX0EvfjeL<br>
rn5Q7q46ehOblJp+94pfHC20dbZUGmcO7Ax9VFGhDeeuxn1baPahuTcuoRsuyz4=<br>
=YRJv<br>
-----END PGP SIGNATURE-----<br>
_______________________________________________<br>
Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org">oisf-users@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" target="_blank">http://suricata-ids.org</a> | Support:<br>
<a href="http://suricata-ids.org/support/" target="_blank">http://suricata-ids.org/support/</a><br>
List:<br>
<a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
Training now available: <a href="http://suricata-ids.org/training/" target="_blank">http://suricata-ids.org/training/</a><br>
_______________________________________________<br>
Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org">oisf-users@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" target="_blank">http://suricata-ids.org/support/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
Training now available: <a href="http://suricata-ids.org/training/" target="_blank">http://suricata-ids.org/training/</a><br>
</div></div></blockquote></div><br></div>