23. Components » Flow Filter

The functionality of Flow Filter is described in depth in the Choosing a Method of DDoS Mitigation chapter. Unlike Packet Filter, which inspects every packet, Flow Filter obtains traffic data directly from Flow Sensor.

To add a Flow Filter, click the [+] button in the title bar of the Configuration » Components panel. To configure an existing Flow Filter, go to Configuration » Components, click its name, and adjust its settings as required.

FLOW_FILTER_CONFIGURATION

The Flow Filter Configuration window opens on a form whose Filter Name and Filter Server are mandatory: [Save] stays greyed out until both of them are filled in. Flow Filter has neither a Capture Engine nor a Sniffing Interface, because it does not capture packets itself.

Flow Filter Configuration parameters:

Filter Name – Assign a short, descriptive name to easily identify the Flow Filter. The colored square inside the field sets the color used by the Filter in graphs; every new Flow Filter starts with a random color
Device Group – (Optional) A label for organizing components, such as by location or characteristics, or to permit roles-based access. The combo box is editable, so you can type a new group instead of selecting an existing one
Filter Server – Choose a server that meets the minimum system requirements for running the Flow Filter. The button on the right opens the configuration of that server
Filtering Interface – Select on which interface to apply the filtering rules. It defaults to None:
None – Detects and reports filtering rules but does not apply them. It greys out the Inbound Interface, the Outbound Interface, the Netfilter Firewall and the Hardware Offload, and the Console resets the last two to Disabled when you save
Inbound interface – Applies filtering on the Inbound Interface, which becomes mandatory
Outbound interface – Applies filtering on the Outbound Interface, which becomes mandatory
Inbound Interface – Enter the interface receiving incoming (ingress) traffic. This parameter can be omitted if Filtering Interface is the same as Outbound Interface. For bridged interfaces, prepend “physdev:” to the interface name
Outbound Interface – Cleaned traffic is sent to the downstream router/switch via this interface, which should have a route to the default gateway. Omit if Filtering Interface is the same as Inbound Interface. For bridged interfaces, prepend “physdev:” to the interface name

The Mitigation section selects which firewalls carry out the filtering rules. Each one has an options button on its right that becomes available once the firewall is enabled.

BGP Flowspec – Choose the policy to apply when sending BGP Flowspec announcements via a Response:
Disabled – Flow Filter does not send Flowspec announcements
Filtering rules drop matched traffic. Valid traffic is accepted – Matched traffic is discarded by the router; everything else passes
Filtering rules rate-limit matched traffic. Valid traffic is accepted – The rate-limit policy applies only to bits/s anomalies; for pkts/s anomalies, any matched traffic is fully discarded
Netfilter Firewall – Flow Filter utilizes the Netfilter framework in the Linux kernel for software-based packet filtering and rate limiting. Because Flow Filter avoids the connection tracking of stateful firewalls, it operates very quickly and remains highly flexible. It is greyed out while the Filtering Interface is None:
Disabled – Flow Filter detects/reports rules but does not invoke the Netfilter firewall
Filtering rules drop matched traffic. Valid traffic is accepted – Flow Filter detects/reports/applies filtering rules via Netfilter. If a rule is not whitelisted, matched traffic is blocked; everything else passes
Filtering rules drop matched traffic. Valid traffic is rate-limited – Flow Filter applies filtering rules, dropping non-whitelisted traffic and rate-limiting the rest. Netfilter only supports pkts/s thresholds, and some kernels fail above 10000 pkts/s
Filtering rules rate-limit matched traffic. Valid traffic is accepted – Flow Filter rate-limits matched traffic to the threshold. Netfilter does not support bits/s thresholds; some kernels fail above 10000 pkts/s
Apply the default Netfilter chain policy – For testing only. Flow Filter detects/reports rules, but all rules have the RETURN target
The options button opens Netfilter Firewall Options:
PACKET_FILTER_OPTIONS_NETFILTER
Manual Execution – When Enabled, filtering rules are applied only manually, by clicking the Netfilter icon in Reports » Tools » Anomalies
Netfilter Table – The raw option typically offers better performance, but it requires both the Inbound Interface and the Outbound Interface to be set, and it may not work on virtual interfaces. The filter option is the default, and it is usually slower
Netfilter Chain – Use FORWARD if the server forwards traffic, or INPUT if it doesn’t. It is greyed out while the Netfilter Table is set to raw, which always uses FORWARD
Operating Layer – Choose OSI Layer 2 if the server is configured as a bridge, OSI Layer 3 otherwise
Hardware Offload – Choose a NIC hardware-filtering option if available. Because hardware filters don’t use CPU cycles, they can complement the Netfilter Firewall for better performance. It is greyed out while the Filtering Interface is None:
Disabled – No hardware filters are applied
Chelsio T5+ 10/40/100 Gigabit adapter with LE-TCAM filters – Uses the cxgbtool utility to apply up to 487 filtering rules for source/destination IPv4/IPv6 addresses, source/destination TCP/UDP ports, and IP protocols. The utility can be installed by the Chelsio Unified Wire driver. Drop counters are available for packets, not for bytes
Mellanox ConnectX NIC with OFED driver – Uses the ethtool utility to apply up to 924 rules for source/destination IPv4/IPv6 addresses, source/destination TCP/UDP ports, and IP protocols. The utility must be installed by the OFED driver driver in /opt/mellanox/ethtool/sbin/. No drop counters available
Intel x520+ 1/10/40 Gigabit adapter configured to block IPv4 sources – Programs the Intel chipset to drop IPv4 source IPs. Up to 4086 hardware filters; no drop counters
Intel x520+ 1/10/40 Gigabit adapter configured to block IPv4 destinations – Programs the Intel chipset to drop IPv4 destination IPs. Up to 4086 hardware filters; no drop counters
The options button opens Hardware Offload Options:
PACKET_FILTER_OPTIONS_HW
Manual Execution – When Enabled, filtering rules are applied only manually, by clicking the NIC chipset icon in Reports » Tools » Anomalies

The Whitelist section contains a set of rules that prevent critical traffic from being blocked.

Whitelist Template – Leave it on None to give this Flow Filter a private set of rules, or select a Whitelist Template to share one set of rules between several components. Selecting a template loads its rules into the grid and makes them read-only; the button on its right opens the configuration of that template
● [Add Rule], [Edit Rule] and [Delete Rule] – Manage the private rules of the Flow Filter. They are greyed out while a Whitelist Template is selected, and a rule can also be edited by double-clicking it. The whitelisting rules and their columns are described in the Whitelist Template chapter
Comments – (Optional) A collapsed section at the bottom that stores internal notes about this Flow Filter. These notes are not displayed elsewhere

[Save] writes the configuration, and [Delete] — shown only after the Flow Filter has been saved once — removes it after asking for confirmation. A Flow Filter that a Reports » Dashboards widget, a Filter Cluster, a Scheduled Reports entry or a Response action still refers to cannot be deleted; the Console names what uses it.

Enable the Flow Filter by clicking the on/off button next to its name in Configuration » Components. If a traffic anomaly triggers the Response action “Detect filtering rules and mitigate the attack with Wanguard Filter”, a Flow Filter instance is launched automatically. If there are no anomalies requiring a Filter instance, Reports » Devices » Overview displays “No active instance”.

Note

You can test any firewall supported by Flow Filter in Reports » Tools » Firewall by clicking [Add Firewall Rule].

23.1. Flow Filter Troubleshooting

✔ If the server is not switching packets although it should function as a network bridge, follow the steps required by your Linux distribution and make sure the following commands are executed during startup:
[root@localhost ~]# sysctl -w net.bridge.bridge-nf-call-ip6tables=1
[root@localhost ~]# sysctl -w net.bridge.bridge-nf-call-iptables=1
[root@localhost ~]# sysctl -w net.bridge.bridge-nf-filter-vlan-tagged=1
✔ If the server is not routing packets although it should function as a router, follow the steps required by your Linux distribution and make sure the following commands are executed during startup. To inject the packets back into the network, set a core router as default gateway, reachable through the Outbound Interface, either directly (recommended) or through a GRE or IP-in-IP tunnel
[root@localhost ~]# sysctl -w net.ipv4.ip_forward=1
[root@localhost ~]# sysctl -w net.ipv4.conf.all.forwarding=1
[root@localhost ~]# sysctl -w net.ipv4.conf.default.rp_filter=0
[root@localhost ~]# sysctl -w net.ipv4.conf.all.rp_filter=0
✔ Go to Help » Software Updates to make sure that you are running the latest version of the software
✔ To view the traffic counters for each Netfilter or Chelsio filtering rule, go to Reports » Tools » Firewall
✔ To see the filtering rules applied by the Netfilter firewall, execute on CLI as root:
[root@localhost ~]# iptables -L -n -v && iptables -L -n -v -t raw
To delete all chains:
[root@localhost ~]# for chain in `iptables -L -t raw | grep wanguard | awk '{ print $2 }'`; do iptables -X $chain; done
✔ To view the filtering rules applied on the Intel 82599 chipset:
[root@localhost ~]# ethtool --show-ntuple <filtering_interface>
or, for kernels >3.1:
[root@localhost ~]# ethtool --show-nfc <filtering_interface>
✔ To ensure that filtering rules can be applied on the Intel 82599 chipset, load the ixgbe driver with the parameter FdirPballoc=3. To prevent getting Location out of range errors from the ixgbe driver, load it with the right parameters in order to activate the maximum number of 8k filtering rules
✔ To view filtering rules applied on the Chelsio T4+ chipset:
[root@localhost ~]# cxgbtool <filtering_interface> filter show
✔ If the Netfilter’s performance is too low, check if nf_conntrack is used and disable it, if possible. Packet Filter uses only stateless firewalls
✔ The event log error License key not compatible with the existing server indicates that the server is unregistered and you need to send the string from Configuration » Servers » [Server] » Hardware Key to sales@andrisoft.com