Project

General

Profile

Actions

Feature #7701

open
VJ VJ

firewall: configurable default policies

Feature #7701: firewall: configurable default policies

Added by Victor Julien about 1 year ago. Updated 7 days ago.

Status:
Resolved
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

For discussion. There are 2 ideas here:
1. allow different actions than plain drop: e.g. reject.
2. allow default accept:hook hooks so we can insert new hooks w/o breaking existing rulesets

Also, so far it seems like the request_started/response_started hooks would most likely fit a default accept:hook as well.


Subtasks 1 (1 open0 closed)

Feature #8574: firewall: configurable default policies (8.0.x backport)In ReviewVictor JulienActions

Related issues 5 (3 open2 closed)

Related to Suricata - Story #7583: 9.0.0: usecase: improve firewall usecaseAssignedVictor JulienActions
Related to Suricata - Feature #8480: firewall: allow specifying multiple actionsResolvedVictor JulienActions
Related to Suricata - Feature #8566: firewall: support generating alerts on default policyIn ReviewVictor JulienActions
Has duplicate Suricata - Feature #8203: firewall: add configuration option for a reject default action.RejectedVictor JulienActions
Has duplicate Suricata - Feature #8281: Add reject as a default action for firewall modeRejectedActions
Actions

Also available in: PDF Atom