Guest User!

You are not Sophos Staff.

[8.940][ANSWERED] IPS blocking bittorrent tracker and scrapper connections

New with 8.840016.  IPS blocking bittorrent from both tracker connections and scrapper requests.  Reason for both:  "Potential Corporate Privacy Violation."  Did not happen before this version.

IDS by default blocks bittorrent from connecting to tracker.  Rule invoked is 2180:



2012:05:01-23:33:40 astaro snort[2341]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="PUA-P2P BitTorrent announce request" group="500" srcip="***.***.xx.xx" dstip="xx.xx.***.***" proto="6" srcport="62588" dstport="80" sid="2180" class="Potential Corporate Privacy Violation" priority="1" generator="1" msgid="0"




IDS by default blocks bittorrent from connecting to scraper.  Rule involved is 16281:



2012:05:01-23:39:42 astaro snort[2341]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="PUA-P2P BitTorrent scrape request" group="500" srcip="***.***.xx.xx" dstip="xx.xx.xx.xx" proto="6" srcport="62806" dstport="80" sid="16281" class="Potential Corporate Privacy Violation" priority="1" generator="1" msgid="0" 



Disabling both rules allows bittorent to work correctly.


********  EDIT

Mod - please change title from IDS to IPS.  My typo, sorry.
Parents Reply Children
  • Hi all,

    Snort ID 2180/16282 is generated when network traffic that indicates BitTorrent is being used.

    The use of BitTorrent may be prohibited by corporate policy in some network environments.

    So if you like you can set the rule to 'alert only' or disable it completely in the webinterface:
    Network Protection>Intrusion Prevention>Advanced>Modified rules

    Same post here.

    I hope this was helpful,
    Lukas
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?