Project

General

Profile

Actions

Support #3224

closed
DC DC

What happens to packets

Support #3224: What happens to packets

Added by Dan Collins almost 7 years ago. Updated over 4 years ago.

Status:
Closed
Priority:
Low
Assignee:
Affected Versions:
Label:
Beginner

Description

In Inline mode, what happens to a packet when there are no matching rules?

AH Updated by Andreas Herz almost 7 years ago Actions #1

  • Status changed from New to Feedback
  • Assignee set to Dan Collins
  • Target version set to Support

What inline mode do you run?
But in general if no rule matches the packet won't be dropped and accepted/forwarded.

DC Updated by Dan Collins almost 7 years ago Actions #2

IPS. Thanks

DC Updated by Dan Collins almost 7 years ago Actions #3

As a follow up to that. For the purpose of memory and performance, if I want all UDP traffic to pass, is it better to use a pass rule, bypass rule, or no rule.

DC Updated by Dan Collins almost 7 years ago Actions #4

Oh, that right, bypass doesn't work with UDP, correct?

AH Updated by Andreas Herz over 4 years ago Actions #5

  • Status changed from Feedback to Closed

Hi, we're closing this issue since there have been no further responses.
If you think this issue is still relevant, try to test it again with the
most recent version of suricata and reopen the issue. If you want to
improve the bug report please take a look at
https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Reporting_Bugs

Actions

Also available in: PDF Atom