Security #5571
closed
ips: encapsulated packet logged as dropped, but not actually dropped
Added by Jean-Baptiste Laplace about 2 years ago.
Updated almost 2 years ago.
Description
We just upgraded from Suricata 6.0.6 setup in IPS with NFQUEUE to Suricata 6.0.8 with the same setup.
We have a drop rule in place (same rule since 6.0.6).
When we initiate traffic from the Suricata instance itself to the site that match the drop rule we get the following (correct) behavior:
- fast.log logs the drop entry
- The traffic is actually dropped
When we initiate traffic from outside the Suricata (and traffic flows through the Suricata) we see the following behavior:
- fast.log logs the drop entry
- The traffic is NOT dropped
I wanted to mention that when the traffic is initiated from outside the Suricata; we use geneve encapsulation.
This is on ubuntu 20.04.
After reverting back to 6.0.6, everything works again as expected.
- Assignee changed from OISF Dev to Juliana Fajardini Reichow
We are seeing the same thing on Amazon Linux 2, GENEVE encapsulated traffic from an AWS Gateway Load Balancer is not dropped even when matched/logged as such on v6.0.8, but it is after downgrading back to v6.0.6.
On v6.0.8 locally initiated traffic is dropped when it matches a drop rule, it's only the GENEVE traffic that isn't.
This is on Amazon Linux 2 using the RPM packages from https://copr.fedorainfracloud.org/coprs/g/oisf/suricata-latest/
- Status changed from New to Assigned
- Priority changed from Normal to High
- Target version changed from TBD to 6.0.9
- Status changed from Assigned to In Progress
- Assignee changed from Juliana Fajardini Reichow to Victor Julien
- Target version changed from 6.0.9 to 7.0.0-beta1
- Label Needs backport to 6.0 added
- Subject changed from Suricata in IPS mode with NFQUEUE we can see the DROP in fast.log but the packet still goes through to ips: encapsulated packet logged as dropped, but not actually dropped
- Status changed from In Progress to In Review
- Status changed from In Review to Resolved
- Label deleted (
Needs backport to 6.0)
- Related to Bug #5633: Pass rules on 6.0.8 are generating alert events when passing tunneled traffic added
- Status changed from Resolved to Closed
- Tracker changed from Bug to Security
- Severity set to HIGH
Also available in: Atom
PDF