Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
68 changes: 48 additions & 20 deletions doc/userguide/firewall/firewall-design.rst
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ Application layer tables
~~~~~~~~~~~~~~~~~~~~~~~~

If applayer is available, rules from the following tables apply. The tables for the
application layer are per app layer protocol and per protocol state. e.g. ``http:request_line``.
application layer are per app layer protocol and per protocol state. e.g. ``http1:request_line``.


.. table::
Expand Down Expand Up @@ -349,29 +349,57 @@ The example below accepts ARP again, using this mechanism.
Default policies
================

Each hook has a default policy. By default ``packet:filter`` enforces a ``drop:packet`` policy and the
``app:filter`` hooks applies ``drop:flow``.
Each hook has a default policy applied to traffic that no firewall rule handled.
By default ``packet.filter`` enforces ``drop:packet``, ``packet.pre-flow`` and
``packet.pre-stream`` enforce ``accept:hook``, and every ``app`` hook enforces
``drop:flow``.

The policies can be configured in ``firewall`` block in the config.

Example for ``packet:filter``, to use reject instead of drop::
Defaults are configured in the ``firewall.policies`` block. A ``default-policy``
may be given at several levels; for any hook the most specific present setting
wins::

firewall:
policies:
packet-filter: [ "reject:packet" ]


Example for DNS::
default-policy: ["accept:hook"] # global fallback (all hooks)
packet:
default-policy: ["drop:packet"] # fallback for packet hooks
filter: ["drop:packet"]
pre-flow: ["accept:hook"]
pre-stream: ["accept:hook"]
app:
default-policy: ["drop:flow"] # fallback for all app hooks
dns:
default-policy: ["drop:flow"] # fallback for dns hooks
request-started: ["accept:hook"]
request-complete: ["drop:flow", "alert"]
response-started: ["accept:tx"]

Protocols whose hooks are grouped into sub states, such as HTTP/2, take an extra
level for the sub state name::

firewall:
policies:
dns:
request-started: ["accept:hook"]

# Drop and alert on all DNS requests that are not allowed in
# firewall.rules.
request-complete: ["drop:flow", "alert"]

# Accept all responses.
response-started: ["accept:tx"]

app:
http2:
default-policy: ["drop:flow"] # fallback for all http2 hooks
stream:
default-policy: ["drop:flow"] # fallback for http2 stream hooks
request-started: ["accept:hook"]
global:
request-started: ["accept:hook"]

Precedence:

* packet hook: ``packet.<hook>`` > ``packet.default-policy`` >
``policies.default-policy`` > built-in (``drop:packet`` or ``accept:hook``)
* app hook: ``app.<proto>.<hook>`` > ``app.<proto>.default-policy`` >
``app.default-policy`` > ``policies.default-policy`` > built-in (``drop:flow``)
* app hook in a sub state: ``app.<proto>.<sub state>.<hook>`` >
``app.<proto>.<sub state>.default-policy`` > ``app.<proto>.default-policy`` >
``app.default-policy`` > ``policies.default-policy`` > built-in (``drop:flow``)

An action scope must be valid for the hook it is applied to. For example,
defining ``accept:tx`` as a global default policy will fail to start Suricata,
because ``packet`` policies do not accept ``tx``.
Cover such hooks with a more specific setting so the incompatible default never
reaches them.
59 changes: 30 additions & 29 deletions doc/userguide/firewall/firewall-example.rst
Original file line number Diff line number Diff line change
Expand Up @@ -67,35 +67,36 @@ In the example below: the config auto accepts various hooks, leaving just ``http

firewall:
policies:
http:
request-started:
- "accept:hook"
request-line:
- "drop:flow"
- "alert"
request-headers:
- "drop:flow"
- "alert"
request-body:
- "accept:hook"
request-trailer:
- "accept:hook"
request-complete:
- "accept:hook"

response-started:
- "accept:hook"
response-line:
- "drop:flow"
- "alert"
response-headers:
- "accept:hook"
response-body:
- "accept:hook"
response-trailer:
- "accept:hook"
response-complete:
- "accept:hook"
app:
http1:
request-started:
- "accept:hook"
request-line:
- "drop:flow"
- "alert"
request-headers:
- "drop:flow"
- "alert"
request-body:
- "accept:hook"
request-trailer:
- "accept:hook"
request-complete:
- "accept:hook"

response-started:
- "accept:hook"
response-line:
- "drop:flow"
- "alert"
response-headers:
- "accept:hook"
response-body:
- "accept:hook"
response-trailer:
- "accept:hook"
response-complete:
- "accept:hook"


::
Expand Down
6 changes: 5 additions & 1 deletion rust/sys/src/sys.rs
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,11 @@ pub enum AppProtoEnum {
}
pub type AppProto = u16;
extern "C" {
#[doc = " \\brief Maps the ALPROTO_*, to its string equivalent.\n\n \\param alproto App layer protocol id.\n\n \\retval String equivalent for the alproto."]
#[doc = " \\brief Maps the ALPROTO_*, to its registered string equivalent.\n \\param alproto App layer protocol id.\n \\retval String equivalent for the alproto."]
pub fn AppProtoToStringRaw(alproto: AppProto) -> *const ::std::os::raw::c_char;
}
extern "C" {
#[doc = " \\brief Maps the ALPROTO_*, to its normalized string equivalent.\n\n \\param alproto App layer protocol id.\n\n \\retval String equivalent for the alproto."]
pub fn AppProtoToString(alproto: AppProto) -> *const ::std::os::raw::c_char;
}
extern "C" {
Expand Down
10 changes: 10 additions & 0 deletions src/app-layer-protos.c
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,16 @@ typedef struct AppProtoStringTuple {

AppProtoStringTuple *g_alproto_strings = NULL;

const char *AppProtoToStringRaw(AppProto alproto)
{
const char *proto_name = NULL;
if (alproto < g_alproto_max) {
DEBUG_VALIDATE_BUG_ON(g_alproto_strings[alproto].alproto != alproto);
proto_name = g_alproto_strings[alproto].str;
}
return proto_name;
}

const char *AppProtoToString(AppProto alproto)
{
const char *proto_name = NULL;
Expand Down
9 changes: 8 additions & 1 deletion src/app-layer-protos.h
Original file line number Diff line number Diff line change
Expand Up @@ -178,7 +178,14 @@ static inline AppProto AppProtoCommon(AppProto sigproto, AppProto alproto)
}

/**
* \brief Maps the ALPROTO_*, to its string equivalent.
* \brief Maps the ALPROTO_*, to its registered string equivalent.
* \param alproto App layer protocol id.
* \retval String equivalent for the alproto.
*/
const char *AppProtoToStringRaw(AppProto alproto);

/**
* \brief Maps the ALPROTO_*, to its normalized string equivalent.
*
* \param alproto App layer protocol id.
*
Expand Down
4 changes: 1 addition & 3 deletions src/detect-engine.c
Original file line number Diff line number Diff line change
Expand Up @@ -885,13 +885,11 @@ const char *DetectEngineAppHookToName(
int DetectEngineAppHookToSmlist(
const AppProto p, const uint8_t sub_state, const uint8_t state, const uint8_t direction)
{
const char *app_proto = AppProtoToString(p);
const char *app_proto = AppProtoToStringRaw(p);
if (app_proto == NULL) {
SCLogError("unknown app_proto %u", p);
return -1;
}
if (strcmp(app_proto, "http") == 0)
app_proto = "http1";

char generic_hook_name[256];
if (sub_state == 0) {
Expand Down
Loading
Loading