Project

General

Profile

Actions

Feature #6260

open

Support flow matching excluding packet recursion level

Added by Cole Dishington over 1 year ago. Updated about 1 month ago.

Status:
In Review
Priority:
Normal
Target version:
Effort:
low
Difficulty:
low
Label:

Description

Add config for controlling the use of packet recursion level in the flow (and defrag) hashing. Packet recursion should be excluded from flow matching if egress packet pickup of tunneled packets occurs before the kernel has put the headers on, like when using netmap pipes, and the suricata device is a tunnel termination point.

Actions

Also available in: Atom PDF