Project

General

Profile

Actions

Feature #6260

open

Support flow matching excluding packet recursion level

Added by Cole Dishington 9 months ago. Updated about 2 months ago.

Status:
In Review
Priority:
Normal
Target version:
Effort:
low
Difficulty:
low
Label:

Description

Add config for controlling the use of packet recursion level in the flow (and defrag) hashing. Packet recursion should be excluded from flow matching if egress packet pickup of tunneled packets occurs before the kernel has put the headers on, like when using netmap pipes, and the suricata device is a tunnel termination point.

Actions

Also available in: Atom PDF