0003850: SNORT isn't blocking RDP
2011-06-03
0003850: SNORT isn't blocking RDP
Going to :

Services => Intrusion Prevention, editing auto/emerging-policy.rules (Search with RDP) and setting drop for all this three rules, just as shown in the screenshot, the RDP works without problem, instead of dropping the RDP requests and responses.

On outgoing the rule for my IP is set to Allow with IPS.
2.4 full up to date mini.

NOTE: didn't check if the packets were really hitting SNORT chain or not.
rdp-drop.png
Issue History
> NOTE: didn't check if the packets were really hitting SNORT chain or not.

If you want to drop RDP protocol you must get the traffic to RDP port pass through snort. In this case why not just close the port? :)

The real use would be to force all the traffic (any destination port) through snort and then snort should be able to detect RDP protocol even if the port is not the default one.
By default not all the traffic (outgoing or incoming) is passing through snort that's probably the reason why it seems not to work.
My idea of use would be to prevent people on my network from acessing RDP servers on alternate ports without my consent.

In my case, all outbound traffic is going through snort.