Project

General

Profile

Actions

Bug #1742

closed

vlan use-for-tracking including Priority in hashing

Added by Andrew Brown almost 9 years ago. Updated almost 9 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

I had an issue on my switch until today where some packets entering the switch were getting tagged with Priority 2, and others were not (still Priority 0) even though every interface had a priority of 2 set. This was causing Suricata to split my streams when vlan: use-for-tracking was set to true.

While I think it's probably an abnormal practice to have different priorities on packets going different directions in a stream, I think it is counter-intuitive to break the flow on that. But if this is expected then please close this ticket.

I've attached a screenshot of the two packets in case that helps.


Files

Priorities.png (73.3 KB) Priorities.png 2 consecutive packets in a stream with different 802.1p priorities, which breaks the stream in suricata. Andrew Brown, 03/10/2016 08:26 PM
Actions #1

Updated by Victor Julien almost 9 years ago

Are you able to (private) share a small pcap? Preferably with a single TCP session with different priorities.

Actions #2

Updated by Andrew Brown almost 9 years ago

PCAP sent via email this morning. Let me know if it is sufficient.

Actions #3

Updated by Victor Julien almost 9 years ago

  • Status changed from New to Assigned
  • Assignee set to Victor Julien
  • Target version set to 70
Actions #5

Updated by Victor Julien almost 9 years ago

  • Status changed from Assigned to Closed
  • Target version changed from 70 to 3.0.1RC1
Actions

Also available in: Atom PDF