CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-11
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 73
Rep Power: 4
gfont96 has an average reputation (10+)
Default Strange SmartDefense entries

Hello All,

Like a good chap I was going through firewall logs and saw the following;

Number: 22816
Date: 11Dec2006
Time: 2:14:05
Product: SmartDefense
Attack Name: Storm Center Block List Enforcement
Attack Information: Packet originated from a host on the DShield block list
Origin: fw-module
Type: Log
Action:
Service: 1026
Source: somehost.net (x.x.x.x)
Destination: x.x.x.x.
Protocol: udp
Information: Total logs: 2
Suppressed logs: 1

These entries show as green (like accepted) but there is nothing in the interface column.

Should I be worried !

Cheers,

George
Reply With Quote
  #2 (permalink)  
Old 2006-12-11
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 810
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Strange SmartDefense entries

It looks like you've configured automatic blocking based on DShield's block list. Those lists are based on reports of bad traffic from various netblocks - e.g. persistent worm traffic.

If you're happy doing that, then it's OK. Depends what your site policy is. Looks like maybe you have it configured just to log, not drop the traffic.

Was it traffic that you consider legitimate traffic?
Reply With Quote
  #3 (permalink)  
Old 2006-12-12
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 73
Rep Power: 4
gfont96 has an average reputation (10+)
Default Re: Strange SmartDefense entries

Hi northlandboy,

I hope you are well. Yes I have the retrieve and block IP list from dshield selected.

Other connections have been made from this source and have been blocked. I wouldn't think this is legitimate traffic.

This one looked odd as it was green as oppose to red. I checked out the IP range and it resolves to hosts in the hideout.net domain. A quick google looks like various hosts in this domain have been trying unusual things and others have been reporting it to the abuse desk of the owners without much joy.

Happened again last night about the same time. We don't have any dealings with the states in this instance we are a uk government body.

I guess I could block the entire IP block for the domain manually in a rule.

I was just interested in why it would appear as accepted as opposed to blocked.

If I have time today I think I'll try and get a snort box out there and see what I find in a capture. Out of interest really.

The host has an ssh port open which I can connect to.

Cheers,

George
Reply With Quote
  #4 (permalink)  
Old 2006-12-13
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 55
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: Strange SmartDefense entries

when we have deny rule, why someone would require to go for stormcentre, i mean cpdshiled configuration?

requires ur views?
Reply With Quote
  #5 (permalink)  
Old 2006-12-14
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 73
Rep Power: 4
gfont96 has an average reputation (10+)
Default Re: Strange SmartDefense entries

Hi Yogi,

I don't know, but I am guessing (hoping) that if a connection comes in from an IP address on the list it gets rejected before being processed by any rules. This may help performance if you have lots of rules.

Cheers,

George
Reply With Quote
  #6 (permalink)  
Old 2006-12-15
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Strange SmartDefense entries

Yes the idea is that your dshield drop rule should be close to the top of your rule base so that, even if it looks like good traffic to another rule, it gets dropped early in the process.
Reply With Quote
  #7 (permalink)  
Old 2006-12-16
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 55
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: Strange SmartDefense entries

good explanation....
but what abt false positives.
?
hth
Yogi
Reply With Quote
  #8 (permalink)  
Old 2006-12-16
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Strange SmartDefense entries

Quote:
Originally Posted by yogi_ccse View Post
good explanation....
but what abt false positives.
Its a very low chance, but you should make sure your admin access to the gateway is above this rule in case you have some infected systems that are attacking the world and you get black listed.

Take a look at www.dshield.org for more information.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:52.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0