Actions
Bug #7053
closedbypass: cannot bypass udp flow from first packet in second direction
Affected Versions:
Effort:
Difficulty:
Label:
Description
From https://forum.suricata.io/t/bypass-does-this-only-work-with-tcp/4660/2
This happens because flow state gets overwritten with established after seeing the second direction
Updated by Philippe Antoine 6 months ago
- Status changed from New to In Review
Updated by Philippe Antoine 6 months ago
- Subject changed from bypass: cannot bypass dup flow from first packet to bypass: cannot bypass udp flow from first packet
Updated by Philippe Antoine 6 months ago
- Subject changed from bypass: cannot bypass udp flow from first packet to bypass: cannot bypass udp flow from first packet in second direction
Updated by Philippe Antoine 6 months ago
By the way, would it make sense to do like SSH ? Once we reach a certain state, all traffic is encrypted, and we bypass automatically...
Updated by Philippe Antoine 5 months ago
- Status changed from In Review to Resolved
Actions