RE: [Snort-users] PPTP and Cisco IPSEC

This is a discussion on RE: [Snort-users] PPTP and Cisco IPSEC within the Snort forums, part of the System Security and Security Related category; The Sourcefire rules policy.rules file includes signatures for PPTP. As for IPSec tunnels, you could easily trigger on the ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-13-2005
Paul Melson
 
Posts: n/a
Default RE: [Snort-users] PPTP and Cisco IPSEC

The Sourcefire rules policy.rules file includes signatures for PPTP.

As for IPSec tunnels, you could easily trigger on the Phase 1 negotiation
packets like this:

alert udp $EXTERNAL_NET 500 -> $HOME_NET 500 (msg:"Site-to-Site IPSec VPN
Phase 1 Traffic"; classtype: attepted-admin; sid:1234001; rev:1;)

alert udp $EXTERNAL_NET !500 -> $HOME_NET 500 (msg:"Client VPN Phase 1
Traffic"; classtype: attempted-admin; sid:1234002; rev:1;)

This would trigger on all phase 1 packets though. To do it right you'd want
to build some content: fields for each signature based on some packet
captures.

PaulM


________________________________

From: snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of Ron Jenkins
Sent: Tuesday, September 13, 2005 3:32 PM
To: snort-users@lists.sourceforge.net
Subject: [Snort-users] PPTP and Cisco IPSEC



Are there any rules written to detect when a VPN PPTP and IPSEC connected
being made to a Cisco Pix?



Thanks.



Ron Jenkins (SnortCP, MCNE, CNE6, MCP, CCNA, CCEA)
Senior Architect
Data Integrity, LLC
"We Integrate People with Solutions"
1724 Dallas Drive
Suite 11
Baton Rouge, La 70806
Office. 225.927.8030
Fax. 225.927.8033
Cell225.931.1632

Email. rjenkins@dibr.net
Web. http://www.dibr.net

(Aanval Reseller and Technology Partner)

http://www.aanval.com/tour/dibr






-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server. Download
it for free - -and be entered to win a 42" plasma tv or your very own
Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 01:31 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0