Project

General

Profile

Actions

Bug #2973

closed

the flow after match the rules

Added by John Smith over 5 years ago. Updated about 1 year ago.

Status:
Rejected
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

if a package match a rule and the rule's action is 'pass',then suricata will set this flow no need to detect. So when I change this rule's action to 'drop',packages won't detect the rules and just pass (even I change the package)

Actions #1

Updated by Victor Julien over 5 years ago

  • Assignee deleted (Victor Julien)
  • Target version deleted (4.1.5)
  • Effort deleted (high)

Can you provide a test case in https://github.com/OISF/suricata-verify ?

Actions #2

Updated by Andreas Herz over 5 years ago

  • Assignee set to John Smith
  • Target version set to TBD
Actions #3

Updated by Philippe Antoine about 1 year ago

  • Status changed from New to Rejected

Looks like the rules were not reloaded, feel free to reopen with more details if needed :-)

Actions

Also available in: Atom PDF