Project

General

Profile

Actions

Bug #7725

closed
JF JF

decode/ipv4: missing ip-in-ip case handling

Bug #7725: decode/ipv4: missing ip-in-ip case handling

Added by Juliana Fajardini Reichow 10 months ago. Updated 8 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

A flow with IPv4 IP in IP traffic won't handle this tunneling case properly.
This leads to potential malicious traffic not triggering alerts, as well as other
inaccuracies in the logs.

Check if this case is also missing in other scenarios.

Waiting to see if the pcap shared can be added to a public SV test.


Subtasks 1 (0 open1 closed)

Bug #7726: decode/ipv4: missing ip-in-ip case handling (7.0.x backport)ClosedJuliana Fajardini ReichowActions

Related issues 2 (2 open0 closed)

Related to Suricata - Bug #4571: Unable to trigger rule by content in case of IPv4 in IPv4 encapsulationFeedbackVictor JulienActions
Related to Suricata - Task #7734: decode: review if any decoders are missing for IPv4 or IPv6NewOISF DevActions

OT Updated by OISF Ticketbot 10 months ago Actions #1

  • Subtask #7726 added

OT Updated by OISF Ticketbot 10 months ago Actions #2

  • Label deleted (Needs backport to 7.0)

JF Updated by Juliana Fajardini Reichow 10 months ago Actions #3

  • Description updated (diff)

JF Updated by Juliana Fajardini Reichow 10 months ago Actions #4

Attempt at a fix shared on GL.

JF Updated by Juliana Fajardini Reichow 10 months ago Actions #5

  • Status changed from New to In Progress
  • Assignee changed from OISF Dev to Juliana Fajardini Reichow

JF Updated by Juliana Fajardini Reichow 10 months ago Actions #6

  • Status changed from In Progress to In Review

JF Updated by Juliana Fajardini Reichow 10 months ago Actions #7

  • Private changed from Yes to No

PA Updated by Philippe Antoine 10 months ago Actions #8

  • Related to Bug #4571: Unable to trigger rule by content in case of IPv4 in IPv4 encapsulation added

PA Updated by Philippe Antoine 10 months ago Actions #9

  • Status changed from In Review to Resolved

JF Updated by Juliana Fajardini Reichow 10 months ago Actions #10

  • Related to Task #7734: decode: review if any decoders are missing for IPv4 or IPv6 added

JF Updated by Juliana Fajardini Reichow 8 months ago Actions #11

  • Status changed from Resolved to Closed
Actions

Also available in: PDF Atom