Actions
Feature #1281
closedlong snort ruleset support for "SC_ERR_NOT_SUPPORTED(225): content length greater than 255 unsupported"
Description
I'm running pfSense 2.1.5-RELEASE (amd64) on (nano) FreeBSD 8.3-RELEASE-p16 with Suricata 2.0.3 pkg v2.0.2 and snortrules-snapshot-2962.tar.gz with snort 'balanced' IPS rules. I'm seeing the following in my logs:
18/9/2014 -- 14:04:21 - <Error> -- [ERRCODE: SC_ERR_NOT_SUPPORTED(225)] - Currently we don't support content length greater than 255. Please split the pattern, if length > 255. The length of the content after normalization is "288".
Could long snort rulecontent be supported sometime in the future?
Actions