Project

General

Profile

Actions

Bug #1778

closed

af_packet: IPS and defrag

Added by Eric Leblond almost 8 years ago. Updated over 4 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

defrag is not compatible with IPS mode as reconstructed packets will be too big when sent over the wire. So we need to warn the user about that. But when defrag is disabled, the cluster_flow load balancing will not work correctly so we need to propose an alternative configuration to improve things.


Related issues 2 (0 open2 closed)

Related to Suricata - Support #2997: IPS AF_Packet mode and decoder invalidClosedCommunity TicketActions
Related to Suricata - Feature #3011: Add new 'cluster_peer' runmode to allow for load balancing by IP header (src<->dst) onlyClosedEric LeblondActions
Actions

Also available in: Atom PDF