I’m curious if anyone can help me with an issue I’m having with snort. We have an Astaro box covering our internet connection with a webserver and workstations behind it. All worked well until I upgraded to 6.203, now when a user tries to access our webserver via it’s DNS name (or external IP address) snort kicks in and blocks it with the following in the Intrusion Protection System log:
2006:06:19-16:54:47 (none) snort[20617]: [116:151:1] (snort decoder) Bad Traffic Same Src/Dst IP {PROTO006} (our IP Address):80 -> (our IP Address):35782
If the user punches in the internal IP address of the server then everything works fine, but most people around here aren’t happy with that answer, anyone have a suggestion?
I tried looking through the Intrusion Protection rules but couldn’t find anything, not sure if it’s somewhere else or I’m just blind.
This thread was automatically locked due to age.