Snort floods with ICMP security alerts

Moment I enable Morce on TOS 6.0.4, my logs get hammered with one rule and I have no idea how to disable it, generally I don’t care about ICMP requests on my local network or at least I’d like to whitelist MACs. I use it to automatically diagnose problems within the network so no reason for router to go haywire and lag because of it.

I’ve tried to use just limited rules in etc/config/morce, but that doesn’t do a thing.

config config 'et'
    list rules "activex"

Any idea how to ignore ICMP rules? Thanks.

4 Likes

Installed it, and ( nOOb here ) was hoping for some sort of GUI. Like Pakon for example…

Wait for the hundreds of notifications in reforis :slight_smile:

Uhm…is this serious?
Cause my syslog suddenly was one big torrent/flood of warnings…and no clue why , what, how, and why not :slight_smile:
I assume this Morce is something for the cli wizzards.

I too installed it a while ago and I get a lot of similar alerts in the logs, but no notification in reForis or email notification, which I also activated. Then what is that “sh: nil: not found”? For the moment the service is in a state that is still too raw. Uninstalled and will try again in a few months/years.

I probably did some local change to fix the nil error. But I don’t remember what was it…

Yes. The default configuration is very harmful. When you try to dismiss the hundreds of notifications in Reforis, your router will usually run out of memory. But that (“fortunately”) only happens if you fix the nil error.

The error is resolved by enabling notifications in the configuration file. The strange thing is that the notifications still do not come. Have you ever received notifications in reForis?

Yes. Hundreds of them :slight_smile: I finally found the related bug report: Some missing shebang on TOS 6 (#3) · Issues · Turris / morce · GitLab .

1 Like

Good news on the subject. Both problems will be solved: no notification command
manually specified and ignore list for false positives.

2 Likes

In my network I have different alerts in the flood. Documentation on how to supress alerts would be better