You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Suricata内联模式(NetfilterQueue)下基于http.host字段阻断特定网站失效问题求助

Suricata内联模式(NetfilterQueue)下基于http.host字段阻断特定网站失效问题求助

各位大佬好,我遇到了一个Suricata规则的问题,想请教下大家:

  • 我当前Suricata以内联模式运行,启动命令如下:
    /usr/bin/suricata -c /etc/suricata/suricata.yaml -q 0 --pidfile /run/suricata.pid
    
  • Iptables的forward、input、output链已配置关联到NFQUEUE 0,执行验证命令iptables -L | grep NFQUEUE得到输出:
    NFQUEUE    all  --  anywhere             anywhere             NFQUEUE num 0
    
  • 目前互联网访问正常,Suricata日志生成也没问题,而且其他阻断规则(比如ICMP阻断)能正常生效:
    对应的规则内容:
    drop icmp any any -> 1.1.1.1 any (msg:"ICMP detected and blocked";SID:123456;rev:1;)
    
    日志里能看到成功阻断的记录:
    07/20/2023-16:29:10.706271  [Drop] [**] [1:123456:1] ICMP detected and blocked [**] [Classification: (null)] [Priority: 3] {ICMP} 192.168.4.12:8 -> 1.1.1.1:0
    07/20/2023-16:31:26.426087  [Drop] [**] [1:123456:1] ICMP detected and blocked [**] [Classification: (null)] [Priority: 3] {ICMP} 192.168.4.12:8 -> 1.1.1.1:0
    

但我想通过http.host字段阻断特定网站的规则却完全不起作用,规则内容是这样的:

drop http $HOME_NET  any -> $EXTERNAL_NET  any (http.host; content:"www.wp.pl"; msg:"matching HTTP denylisted FQDNs";)

我实在搞不清楚是规则本身写错了,还是Suricata还有什么必要的配置没开启,有没有大佬能帮我分析下问题出在哪?提前谢谢大家了!

备注:内容来源于stack exchange,提问作者admfotad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 07:43:01