2023-02-07T09:34:25.605081+0100 2008064 blocked 2.16.186.27 80 192.168.17.21 50532 ET DELETED Nginx Server with no version string - Often Hostile Traffi
2023-02-07T09:33:21.699912+0100 2027390 blocked 192.168.28.2 49791 104.108.184.217 80 ET USER_AGENTS Microsoft Device Metadata Retrieval Client User-Agent
The IP "2.16.186.27" is the source. How can it be reach our internal "192.168.17.21" IP Address on port 80
Why is the Interface row empty on 50% of the alerts?
QuoteWhy is the Interface row empty on 50% of the alerts?traffic originated by firewall host? (like dns queries)
2023-02-08T08:37:47.488728+0100 2000428 blocked 209.197.3.8 80 192.168.28.2 54650 ET POLICY ZIP file download 2023-02-08T08:37:43.633795+0100 2000428 blocked 178.79.242.0 80 192.168.28.2 54648 ET POLICY ZIP file download
traffic from server (2.16.186.27 80) to client (192.168.17.21 50532) contains Server header with missing nginx version.
2023-02-08T08:24:23.581517+0100 2028371 blocked 192.168.28.2 54610 52.48.126.58 443 ET JA3 Hash - Possible Malware - Fake Firefox Font Update 2023-02-08T08:24:23.581517+0100 2028371 blocked 192.168.28.2 54610 52.48.126.58 443 ET JA3 Hash - Possible Malware - Fake Firefox Font Update 2023-02-08T08:24:16.373773+0100 2000428 blocked 178.79.242.128 80 192.168.28.2 54608 ET POLICY ZIP file download 2023-02-08T08:24:16.373773+0100 2000428 blocked 178.79.242.128 80 192.168.28.2 54608 ET POLICY ZIP file download
No Traffic isnt from the FW itself.
So that is the return channel an thats why source/dest column are switched?
QuoteNo Traffic isnt from the FW itself.well, the more technically correct answer would be: a packet arrives at an interface with a name that cannot be resolved into a friendly interface name. but maybe it can't be converted because the code was not updated when the suricata template was updated a few years ago )I'll try to make a pr. thanks for noticingQuoteSo that is the return channel an thats why source/dest column are switched?yes. rules specify the direction of traffic