Project

General

Profile

Feature #2816

vlan: support more than 2 layers

Added by Tony Gumbrell over 2 years ago. Updated 11 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Protocol

Description

When running 2 x 8100 vlan tags within my data the packets are parsed neatly into the eve.json log file in the format "vlan":[123,987]. We have just added a third tag to this data and despite being able to validate the tags in pcaps, the traffic is no longer be parsed into the eve.json log at all.

Is this a system limitation or a bug?

Thanks

#1

Updated by Victor Julien over 2 years ago

Currently Suricata will only deal with a max of 2 vlans per packet.

#2

Updated by Tony Gumbrell over 2 years ago

Thanks for the speedy response. Is it on the roadmap to resolve this?

#3

Updated by Victor Julien over 2 years ago

  • Tracker changed from Bug to Feature
  • Subject changed from 3 VLAN tags breaks eve.json to vlan: support more than 2 layers
  • Affected Versions deleted (4.1)

Not yet, but you're not the first to bring this up. So I think it should be addressed.

#4

Updated by Andreas Herz about 2 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
#5

Updated by Victor Julien over 1 year ago

  • Target version changed from TBD to 6.0.0beta1
#6

Updated by Victor Julien over 1 year ago

  • Label Protocol added
#7

Updated by Victor Julien about 1 year ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Victor Julien
#8

Updated by Victor Julien 11 months ago

  • Target version changed from 6.0.0beta1 to 7.0rc1

Also available in: Atom PDF