NethServer Version: 7.5 final
Module: Suricata
Hey Folks,
i receive rom Evebox Messages like this:
ALERT: ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 126 2 [ ET ]
Timestamp 2018-07-12T20:01:03.296647+0200
Protocol UDP Source 138.201.135.108 :123 Destination 192.168.100.147 :44567
Flow ID 2091986620199229 Signature ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 126 Category Misc Attack Signature ID 1: 2522250 :3384 Severity 2
I guess it is something NTP but what i dont get, i have chronyd installed and up and running. so normal the systems inside the network should be synch with it. Maybe someone has an idea