Project

General

Profile

Actions

Bug #769

closed

Be sure to always apply verdict to NFQ packet

Added by Eric Leblond about 11 years ago. Updated almost 11 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

It seems that in some cases, it is possible that Suricata do not verdict a Packet. This is for example the case when the propagation to the other module fails. This could result in some packets getting stuck inside Netfilter queue on kernel side.

We should investigate more deeply into this to be sure we always verdict Packet.

Actions

Also available in: Atom PDF