This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Snort blocking connections to our internal web server

I’m curious if anyone can help me with an issue I’m having with snort.  We have an Astaro box covering our internet connection with a webserver and workstations behind it. All worked well until I upgraded to 6.203, now when a user tries to access our webserver via it’s DNS name (or external IP address) snort kicks in and blocks it with the following in the Intrusion Protection System log:

2006:06:19-16:54:47 (none) snort[20617]: [116:151:1] (snort decoder) Bad Traffic Same Src/Dst IP  {PROTO006} (our IP Address):80 -> (our IP Address):35782

If the user punches in the internal IP address of the server then everything works fine, but most people around here aren’t happy with that answer, anyone have a suggestion?

I tried looking through the Intrusion Protection rules but couldn’t find anything, not sure if it’s somewhere else or I’m just blind.


This thread was automatically locked due to age.
Parents Reply Children
No Data