Project

General

Profile

Actions

Feature #5219

closed

Task #4773: research: IPS behavior wrt resource limits

ips: add 'master switch' to enable dropping on traffic (handling) exceptions

Added by Victor Julien about 2 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

In IPS mode for new setups we should default to "drop-pkt/drop-flow" on all policies. However for smooth upgrades we should probably only do it in a new config. Wonder if we should add a warning in 7 that in 8 this will be enabled also for configs that are not setting the option.


Related issues 3 (1 open2 closed)

Related to Suricata - Feature #5745: exceptions: allow setting via unix-socketNewOISF DevActions
Related to Suricata - Bug #5765: exceptions: midstream flows are dropped if midstream=true && stream.midstream-policy=drop-flowClosedJuliana Fajardini ReichowActions
Related to Suricata - Bug #6169: exceptions: master switch not applied to midstreamClosedJuliana Fajardini ReichowActions
Actions

Also available in: Atom PDF