Project

General

Profile

Actions

Bug #393

closed

Suricata can only load maximum of 101 IP only rules

Added by Lambert Osas over 12 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Hi,

I'm not quite sure if this is a bug suricata configuration issues but I observed that when I tried to load a custom 398 IP based rules, Suricata always throws up errors and can only load 101 rules of the IP rules.

My 398 IP rules are like this:

drop ip [111.222.333.444/25,.........] any -> $HOME_NET any (msg:"DROP Traffic"; reference:url,www.mydomain.com; threshold: type limit, track by_dst, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:24040000; rev:2307;)

Please can someone be kind enough to point me in the right direction.

Thanks.


Files

custom.rules (288 KB) custom.rules Lambert Osas, 01/01/2012 08:31 AM
Actions

Also available in: Atom PDF