Project

General

Profile

Actions

Feature #6261

open

Add GRE as a parsible protocol

Added by Thomas Winter 9 months ago. Updated 6 months ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

This will allow rules wanting to match on GRE packets without having to specify the protocol number specifically.

For example:
alert gre any any -> any any (msg:"gre-decoder-events GRE packet too small"; decode-event:gre.pkt_too_small; sid:2200052; rev:1;)


Related issues 1 (1 open0 closed)

Related to Suricata - Documentation #5660: userguide: add (more) documentation for the GRE protocolNewOISF DevActions
Actions

Also available in: Atom PDF