1. Subscriptions
  2. Services
  3. Hardware
  4. Support

ClearFoundation

Forums
Welcome, Guest
ClearOS drops all traffic ! Network unavailable
(1 viewing) 1 Guest
Go to bottomPage: 1
TOPIC: ClearOS drops all traffic ! Network unavailable
#36869
ClearOS drops all traffic ! Network unavailable 4 Months ago  
Hi,

First of all, I would like to congratulate the team for the work on ClearOS, it's a great product.

I'm using ClearOS v5.2 on the top of my network in gateway mode, with intrusion detection and prevention activated. All worked fine for month, but 2 days ago, ClearOS drops all the traffic of the gateway, resulting in a very bad unavailability of all my services

I took some time to diagnose the problem, and finally solved it by desactivating intrusion detection and prevention services.

No configuration had been made on clearOS before it drops the traffic, so I wonder what had could happened ! Now, I would like to reactivate the intrusion services, but I would like to know exactly what had happened.

Does anybody know this kind of issue ? Where can I find revelant log to trace the problem ?

Thank you,

Ben
Benjamin
Fresh Boarder
Posts: 3
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#36873
Re: ClearOS drops all traffic ! Network unavailable 4 Months ago  
Have a look in /var/log/messages if there is a problem with snort (IDS)/snortsam (IPS) starting, /var/log/secure for when rules are triggered by snort and /var/log/snortsam for any blocks put in by snortsam.
Nick Howitt
Platinum Boarder
Posts: 2824
graphgraph
User Online Now Click here to see the profile of this user
The administrator has disabled public write access.
 
#37422
Re: ClearOS drops all traffic ! Network unavailable 3 Months, 2 Weeks ago  
Hi Nick,

Thank you very much for your answer, and sorry for mine late !

Here's what I can find in the logs about snort :

in /var/log/messages, 2 days before the full drop happens :
Code:

Jan 16 22:30:23 fw1 snort[4079]: S5: Session exceeded configured max bytes to queue 1048576 using 1048792 bytes (server queue). xxx.xxx.xxx.xxx 52369 --> xxx.xxx.xxx.xxx 80 : LWstate 0x
f LWFlags 0x6007 
Jan 16 22:30:24 fw1 snort[4079]: S5: Pruned session from cache that was using 1096408 bytes (closed normally). xxx.xxx.xxx.xxx 52369 --> xxx.xxx.xxx.xxx 80 : LWstate 0xf LWFlags 0x20e00
7



In /var/log/secure, I see a lot of line (>500 in 10 hours) like that on POP3, IMAPS, POP3S. I think it's the problem, but don't know why snort think that. I can see my IP, and I what not bruteforcing this server
Code:

Jan 18 11:51:52 fw1 snort[4815]: [1:2002995:6] ET SCAN Rapid IMAPS Connections - Possible Brute Force Attack [Classification: Misc activity] [Priority: 3]: {TCP} xxx.xxx.xxx.xxx:34261 -> xxx.xxx.xxx.xxx:993



/var/log/snortsam seems normal, no extra activity. I can't see my IP in, but I was blocked.

What do you think ? Tell me if you need more information.

Thanks a lot,

Ben
Benjamin
Fresh Boarder
Posts: 3
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#37436
Re: ClearOS drops all traffic ! Network unavailable 3 Months, 2 Weeks ago  
Odd. I am not too sure about snort. Were you connected internally or externally when it thought it was being brute-forced? For the moment you could try disabling the Scan rules and see if it helps.
Nick Howitt
Platinum Boarder
Posts: 2824
graphgraph
User Online Now Click here to see the profile of this user
The administrator has disabled public write access.
 
#37457
Re:ClearOS drops all traffic ! Network unavailable 3 Months, 2 Weeks ago  
I was connected externally. All the dropped IPs was external too.

How can I disable only the brute force attack detection. On the web front, I can only disable the whole group web-misc. Is it in that category ? It contains 511 rules. Is it possible to fine-grain the selection ?

And I am in a production environnement, so I would like to clearly identify what happened before trying to reactivate IDS/IPS.

How can I dig a bit more to find why snort think there is a bruteforce attack on mails services (POP3, IMAPS, POP3S) ? Is there's a debug mode for snort logging ?

Thanks,

Ben
Benjamin
Fresh Boarder
Posts: 3
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#37458
Re:ClearOS drops all traffic ! Network unavailable 3 Months, 2 Weeks ago  
To disable a rule go to /etc/snort/scan.rules and look for the line with something like "sid: 2002995". Disable it by putting a # at the start of the line then restart snort.

I've no idea about debugging snort itself. It may be a query for your e-mail client provider.
Nick Howitt
Platinum Boarder
Posts: 2824
graphgraph
User Online Now Click here to see the profile of this user
The administrator has disabled public write access.
 
Go to topPage: 1
  get the latest posts directly to your desktop