Teredo tunnel detection is difficult because of the protocol which is too limited.
To avoid miss detection, we can had a port parameter to avoid to run the detection on all flow. The configuration could look like that:
be just like it is now? (auto detection and no settings in yaml)
Most people would prefer auto proto detection.
or I am misinterpreting ?
- Target version set to TBD
- Target version changed from TBD to 70
Pcap in #990 is an example of misdetected teredo.
- Status changed from New to Assigned
- Assignee changed from OISF Dev to Victor Julien
- Priority changed from High to Normal
- Target version changed from 70 to 4.0rc2
- Status changed from Assigned to Closed
Also available in: Atom