# SSH (Secure Shell) to the Internet "rule discrepancy?"

**URL:** <https://discuss.elastic.co/t/ssh-secure-shell-to-the-internet-rule-discrepancy/239094>\
**Category:** SIEM\
**Created:** [June 29, 2020, 10:54am UTC](https://discuss.elastic.co/t/ssh-secure-shell-to-the-internet-rule-discrepancy/239094 "2020-06-29T10:54:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andreas\_Falk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_falk/32/82595_2.png) [@Andreas\_Falk](https://discuss.elastic.co/u/Andreas_Falk)\
**Post date:** [June 29, 2020, 10:54am UTC](https://discuss.elastic.co/t/ssh-secure-shell-to-the-internet-rule-discrepancy/239094/1 "2020-06-29T10:54:51Z")

</div>

Hi,

I am looking to get Cisco FNF (Flexible Netflow) and elastic netflow to play nice with me.  
I don't know if I should report this as a "bug"?  
When using FNF and get direction on internal flows it feels like the signal detection rule:  
"SSH (Secure Shell) to the Internet"

This fires on internal » internal outbound traffic.  
192.168.1.10 » 192.168.2.10:22

```auto
network.transport: tcp and destination.port:22 and ( network.direction: outbound or ( source.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) ))

```

Is this by design, or should it be something like?:

```auto
network.transport: tcp and destination.port:22 and ( network.direction: outbound and not destination.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) or ( source.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16)))

```

or (without outbound)

```auto
network.transport: tcp and destination.port:22 and source.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16))

```

--  
Regards Falk

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [June 30, 2020, 8:52pm UTC](https://discuss.elastic.co/t/ssh-secure-shell-to-the-internet-rule-discrepancy/239094/2 "2020-06-30T20:52:20Z")

</div>

Hey there Falk,

I spoke to our I&A team about this and they're now tracking this as a rule tuning change for a future release, so thank you for bringing this up! 🙂

All of our detection rules were actually just made available on [github](https://github.com/elastic/detection-rules) earlier today (🎉 ), so if you stumble across anything else rule-related feel free to [open an issue](https://github.com/elastic/detection-rules/issues/new/choose) in that repo and it can be tracked as part of their releases.

Thanks again!  
Garrett

---

<div class="post-metadata">

**Author:** ![Andreas\_Falk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_falk/32/82595_2.png) [@Andreas\_Falk](https://discuss.elastic.co/u/Andreas_Falk)\
**Post date:** [July 6, 2020, 11:34am UTC](https://discuss.elastic.co/t/ssh-secure-shell-to-the-internet-rule-discrepancy/239094/3 "2020-07-06T11:34:39Z")

</div>

Really nice work by the team!

Forking and checking it out now 🙂

--  
Regards Falk

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2020, 11:34am UTC](https://discuss.elastic.co/t/ssh-secure-shell-to-the-internet-rule-discrepancy/239094/4 "2020-08-03T11:34:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
