Project

General

Profile

Actions

Optimization #718

closed

"pass" IP-only rules should bypass detection engine after matching

Added by Victor Julien over 11 years ago. Updated about 11 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

If a "pass" IP-only rule matches, it will also match for all future packets of that flow. Hence, it makes sense to set a flag in the flow to bypass the detection engine.

Actions

Also available in: Atom PDF