Project

General

Profile

Actions

Support #1820

closed

IPS inline host-os-policy

Added by Cleberson Batista almost 8 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Affected Versions:
Label:

Description

I have the suricata in inline mode on a border router with Debian operating system, and I wonder what the best scenario for setting the parameters of host-os-policy, as in the current scenario configuration, has generated several module alerts stream:

- SURICATA TCP duplicated option
- SURICATA STREAM ESTABLISHED packet out of window
- SURICATA STREAM ESTABLISHED invalid ack
- SURICATA STREAM Packet with invalid ack

Current configuration:

- OS: Debian Wheezy

- IP Suricata: 10.100.0.1

- IP network: 10.100.0.0/21,10.190.0.0/24

- IPs internet link: 183.X.X.X,201.X.X.X

- Suricata 3.1

[edit: yaml removed]

Thanks in advance!

Cleberson

Actions

Also available in: Atom PDF