Project

General

Profile

Actions

Bug #4267

closed

output: don't use /etc/protocols

Added by Victor Julien about 3 years ago. Updated almost 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Using /etc/protocols leads to subtle differences in output. E.g. in ICMPv6 we have IPv6-ICMP on Ubuntu, but IPV6-ICMP on FreeBSD 12. Alpine Linux with musl doesn't define SCTP and so on.


Related issues 1 (0 open1 closed)

Related to Suricata - Bug #5072: detect/ip_proto: inconsistent behavior when specifying protocol by stringClosedJeff LucovskyActions
Actions #1

Updated by Jeff Lucovsky about 3 years ago

Suggest using the names/values in the authoritative source: https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml#protocol-numbers-1

Or, did you have something else in mind -- start with ubuntu?

Actions #2

Updated by Jeff Lucovsky almost 3 years ago

  • Status changed from New to Assigned
  • Assignee set to Jeff Lucovsky
Actions #4

Updated by Jeff Lucovsky almost 3 years ago

  • Status changed from Assigned to In Review
Actions #5

Updated by Jeff Lucovsky almost 3 years ago

  • Status changed from In Review to Closed
Actions #6

Updated by Jeff Lucovsky about 2 years ago

  • Related to Bug #5072: detect/ip_proto: inconsistent behavior when specifying protocol by string added
Actions

Also available in: Atom PDF