Project

General

Profile

Actions

Bug #6149

closed

exceptions: 'auto' policy not considered valid value in IDS mode

Added by Juliana Fajardini Reichow 11 months ago. Updated 11 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

When in IDS mode, Suricata issues a warning that 'auto' isn't a valid config option, and proceeds to setting
the master switch (and possibly other values, too) to `ignore` (see image attached).

Two fixes needed:
- 'auto' is valid, it just defaults to 'ignore' in IDS mode, so no warning should happen
- the "exception policy: exception policy" is confusing, reword the message

The function for parsing the master switch should probably be re-worked to avoid that last part.


Files

image (1).png (40.7 KB) image (1).png Juliana Fajardini Reichow, 06/14/2023 06:34 PM
Actions #1

Updated by Juliana Fajardini Reichow 11 months ago

(Should have been obvious, but hadn't realized: this happens when 'exception-policy' is set to 'auto' in the suricata.yaml file.)

Actions #2

Updated by Juliana Fajardini Reichow 11 months ago

  • Affected Versions 7.0.0-rc2 added
Actions #3

Updated by Juliana Fajardini Reichow 11 months ago

  • Status changed from New to In Review
Actions #4

Updated by Juliana Fajardini Reichow 11 months ago

  • Status changed from In Review to Closed
Actions

Also available in: Atom PDF