# Custom Rule to Allow only web browser traffic on port 80

**URL:** <https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614>\
**Category:** Rules\
**Created:** [August 14, 2021, 9:39am UTC](https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614 "2021-08-14T09:39:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan\_N](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ryan_n/32/927_2.png) [@Ryan\_N](https://forum.suricata.io/u/Ryan_N)\
**Post date:** [August 14, 2021, 9:39am UTC](https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614/1 "2021-08-14T09:39:51Z")

</div>

Hi

VM Version: Ubuntu Desktop 20.04.2  
Suricata Version: 6.0.0 Release

I am running suricata in **IPS** mode with nfq and I have `XAMPP` server running. I’m trying to create a rule that allows http traffic on a web browser with port 80, while blocking all nmap traffic. Is there a signature or content i can specify to accomplish this? Right now I have

```auto
drop tcp any any -> $HOME_NET !80 (msg:"Possible Nmap TCP SYN Scan"; flow:from_client;flags:S; sid:5;rev:1;)

```

which blocks nmap from scanning all ports other than `80`. However, this rule also block out ssh, which I want to do my testing with ssh bruteforcing (and not reveal the port at the same time).

Currently before turning on suricata, I get:

```auto
$ sudo nmap 192.168.233.196
Starting Nmap 7.91 ( https://nmap.org ) at 2021-08-14 
Nmap scan report for 192.168.233.196
Host is up (0.00046s latency).
Not shown: 996 closed ports
PORT STATE SERVICE
21/tcp open ftp
80/tcp open http
443/tcp open https
3306/tcp open mysql
MAC Address: 00:0C:29:C9:25:D3 (VMware)

```

And after I turn it on, I get:

```auto
$ sudo nmap 192.168.233.196
Starting Nmap 7.91 ( https://nmap.org ) at 2021-08-14 
Nmap scan report for 192.168.233.196
Host is up (0.0012s latency).
Not shown: 999 filtered ports
PORT STATE SERVICE
80/tcp open http
MAC Address: 00:0C:29:C9:25:D3 (VMware)

```

Want to accomplish not having ports revealed whilst being **able to access the services** (i.e. 80/tcp and 21/tcp). Thanks!

---

<div class="post-metadata">

**Author:** ![IDSTower](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/idstower/32/861_2.png) [@IDSTower](https://forum.suricata.io/u/IDSTower)\
**Post date:** [August 14, 2021, 9:58am UTC](https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614/2 "2021-08-14T09:58:34Z")

</div>

Dear Ryan,

It is not possible to establish TCP connection without the 3-way handshake that starts with a syn packet.

The rule you provided drops the syn packet (except on port 80) and this prevents the connections from being established (including ssh).

The only way to accomplish what you are trying to do is either to create an allowlist of IPs that can access the services and the rest are blocked.

Or by implementing some network level authentication mechanism (eg: port knocking) which will again requires that you define/customize you clients.

---

<div class="post-metadata">

**Author:** ![Ryan\_N](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ryan_n/32/927_2.png) [@Ryan\_N](https://forum.suricata.io/u/Ryan_N)\
**Post date:** [August 14, 2021, 10:00am UTC](https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614/3 "2021-08-14T10:00:58Z")

</div>

@IDSTower Got it. So there is no way of filtering which is Nmap traffic and which is web browsing if both use http (or 80/tcp) is that right? Thanks!

---

<div class="post-metadata">

**Author:** ![IDSTower](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/idstower/32/861_2.png) [@IDSTower](https://forum.suricata.io/u/IDSTower)\
**Post date:** [August 14, 2021, 10:07am UTC](https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614/4 "2021-08-14T10:07:39Z")

</div>

Yes, however this does not mean you can’t do anything

You can still block some of the nmap scanners by detecting ips that send many syn packet in a short period of time (indicating an ip scanning a full network/host)

---

<div class="post-metadata">

**Author:** ![Ryan\_N](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ryan_n/32/927_2.png) [@Ryan\_N](https://forum.suricata.io/u/Ryan_N)\
**Post date:** [August 14, 2021, 10:10am UTC](https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614/5 "2021-08-14T10:10:06Z")

</div>

@IDSTower I see would you mind pointing me in the right direction for this (blocking differs from dropping packets, correct)? A link would be much appreciated. Thanks

---

<div class="post-metadata">

**Author:** ![IDSTower](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/idstower/32/861_2.png) [@IDSTower](https://forum.suricata.io/u/IDSTower)\
**Post date:** [August 14, 2021, 10:19am UTC](https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614/6 "2021-08-14T10:19:05Z")

</div>

Dropping and blocking is the same from my prospective.

[Take a look here](https://github.com/jpalanco/alienvault-ossim/blob/master/suricata-rules-default-open/rules/1.3.1/emerging.rules/emerging-scan.rules), this files contains rules to detect many scanners including some nmap scanning techniques.

Hope this helps

---

<div class="post-metadata">

**Author:** ![Ryan\_N](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ryan_n/32/927_2.png) [@Ryan\_N](https://forum.suricata.io/u/Ryan_N)\
**Post date:** [August 14, 2021, 10:50am UTC](https://forum.suricata.io/t/custom-rule-to-allow-only-web-browser-traffic-on-port-80/1614/7 "2021-08-14T10:50:01Z")

</div>

ok got it thanks @IDSTower !
