Project

General

Profile

Actions

Support #2998

closed
LI LI

Rules Reload doesn't work properly

Support #2998: Rules Reload doesn't work properly

Added by Leonid Inodin almost 7 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Affected Versions:
Label:

Description

I need to drop icmp traffic from 8.8.8.8 (for example). I have created my own rule file (this rules file name is added to the main config file) with 1 rule: drop icmp 8.8.8.8 any -> $HOME_NET any (msg:"Our Blocking Rule"; priority:1; sid:777;). When I use "kill -USR2 $(pidof suricata)", in suricata.log everything is ok. But ICMP with 8.8.8.8 seems not to be dropped. Why?

PM Updated by Peter Manev almost 7 years ago Actions #1

Seems related to the set up here - https://github.com/StamusNetworks/SELKS/issues/188

AH Updated by Andreas Herz almost 7 years ago Actions #2

  • Status changed from New to Feedback
  • Assignee set to Leonid Inodin
  • Target version set to TBD

It looks like exactly the same, it might be better to either move the conversation here or keep it at github?

We would also need more details about the setup.

PM Updated by Peter Manev almost 7 years ago Actions #3

It is the same. Was reported on github first i think. If not mistaken setting "defrag:no" fixes the issue - https://redmine.openinfosecfoundation.org/issues/2997#change-12370

AH Updated by Andreas Herz over 6 years ago Actions #4

  • Status changed from Feedback to Closed

was also closed at github

VJ Updated by Victor Julien over 6 years ago Actions #5

  • Tracker changed from Bug to Support
Actions

Also available in: PDF Atom