Project

General

Profile

Actions

Support #1534

closed

P2P rules in emerging-p2p.rules not blocking p2p traffic

Added by Ravin Goyal over 8 years ago. Updated almost 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

I have set suricata in inline mode for my host machine only to block p2p traffic and set 'modifysid emerging-p2p.rules "^alert" | "drop" in /etc/oinkmaster.conf and rerun it.

As i can see it can block metafile(.torrent) file but it failed to block p2p traffic of already active torrents.
but some of the rules are logged in fast.log as [DROP] [**]
but still traffic is coming.

I guess most of the rules are not matched
Please sugest something regarding the issue.


Files

fast.log (464 KB) fast.log Ravin Goyal, 08/26/2015 07:32 AM
Actions

Also available in: Atom PDF