# One-way TCP session to handle HTTP requests only

**URL:** <https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3533>\
**Category:** Zeek\
**Created:** [March 25, 2015, 5:11pm UTC](https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3533 "2015-03-25T17:11:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rovnov\_Pavel](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@Rovnov\_Pavel](https://community.zeek.org/u/Rovnov_Pavel)\
**Post date:** [March 25, 2015, 5:11pm UTC](https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3533/1 "2015-03-25T17:11:34Z")

</div>

Hello again!

I’m trying to run installation with client-to-server only traffic visible to Bro. This seems not to break Bro however the following messages fill weird.log:

1427302895.156616 C50xd821xHdTYgVRWj 172.x.x.x 33468 87.252.227.138 41223 data\_before\_established - F bro

1427302895.228297 CqeQYQ1Q4MgbwupuR8 172.x.x.x 45107 62.84.63.46 13871 possible\_split\_routing - F bro

1427302895.228985 CqeQYQ1Q4MgbwupuR8 172.x.x.x 45107 62.84.63.46 13871 data\_before\_established - F bro

1427302895.782191 CiSuNR2tWAfGBpuSxe 172.x.x.x 55007 80.249.82.211 11898 possible\_split\_routing - F bro

1427302895.783376 CiSuNR2tWAfGBpuSxe 172.x.x.x 55007 80.249.82.211 11898 data\_before\_established

Does anyone know how to switch Bro into asymmetric mode? At least can I disable notices that need 2-way session?

Thanks!

Pavel

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [March 25, 2015, 6:27pm UTC](https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3533/2 "2015-03-25T18:27:13Z")

</div>

Unfortunately at this time, we don’t put much attention to asymmetric traffic analysis. This is something I’ve been wanting to do for a long time, but it hasn’t bubbled up high enough on the priority list yet.

Any results you get from asymmetric traffic processing are coincidental, we don’t have any tests or anything that validate that Bro works in any particular scenario with asymmetric traffic.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Rovnov\_Pavel](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@Rovnov\_Pavel](https://community.zeek.org/u/Rovnov_Pavel)\
**Post date:** [March 26, 2015, 6:58am UTC](https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3533/3 "2015-03-26T06:58:32Z")

</div>

Hello Seth,

To bubble up asymmetric traffic analysis higher in the list let me describe our scenario. We would like to analyze ~55Gb/s+ (5Gb/s upstream, 50Gb/s downstream) of web traffic (both HTTP and HTTPS). At layer 7 we need to know hostnames and perhaps URLs visited. In case we analyze upstream only we can reduce hardware requirements greatly.

What causes Bro to be asymmetric intolerant: rule, BinPac,...? What is we disable all rules and leave only rules that solve the task? Will the result be still coincidental?

Thanks for answers!

Pavel

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/one-way-tcp-session-to-handle-http-requests-only/3533/4 "2022-05-06T15:42:33Z")

</div>


