Limiting packet size with CHX-I payload filter

Discussion in 'other firewalls' started by soniak, Jul 5, 2006.

Thread Status:
Not open for further replies.
  1. soniak

    soniak Registered Member

    Joined:
    Jul 5, 2006
    Posts:
    2
    I would like to limit DNS packet size to for example 90 bytes. I made a traffic stream for dst port UDP 53 and associated with payload filter.

    In payload filter I defined bounduaries as:
    start \s (start of packet)
    end \p (end of packet).

    In field If number of bytes after start and before any other flag exceeds: I putted here 90 Connection Flow then I selected Drop packet, close connection and I selected the same for Primary Action.

    Then when I sended to DNS packets with size exceeded 90 bytes, they were not blocked.
    What I'm doing wrong?
     
  2. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
    I can't answer your question soniak, but here's another place to ask if nobody here knows the answer:

    http://fluxgfx.com/ssc/
     
  3. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    soniak,
    The info for the rule looks correct,.. I did re-install CHX-I to check. The rule is working correctly. I think you just need to step back,... have a break,.. and then re-check your rules.
     
  4. soniak

    soniak Registered Member

    Joined:
    Jul 5, 2006
    Posts:
    2
    For now I have only this one rule. I double check everything, and even if I set 1 byte in field with number of bytes, queries are resolved successfully. (I cleaned resolver cache before test).
     
  5. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Hi, I need to go out (work) for a couple of hours,.. when I get back, I will re-istall CHX-I, and remake the rules you mention, and will post them so we can compare. o.k.?
     
  6. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    soniak,
    I have re-installed, and set up the payload rule again, and all working correctly. Have attached image for you to compare rules.
     

    Attached Files:

Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.