Project

General

Profile

Actions

Task #8204

closed
OA VJ

firewall: add tests for hot reload of firewall mode rules

Task #8204: firewall: add tests for hot reload of firewall mode rules

Added by Olu Adeleke 4 months ago. Updated 13 days ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Rule reloading without restarts is not yet supported for firewall mode rules.

This implies that users need to restart Suricata whenever there is a need for to update firewall mode rules, and this can cause interruptions to packet processing, packet losses and cause flows to be re-categorized as midstream.

It would be useful to have some in built support to hot-reload firewall mode rules (similar to what exists for the existing IPS/IDS rules) without need for restarts.


Subtasks 1 (0 open1 closed)

Task #8409: firewall: add tests for hot reload of firewall mode rules (8.0.x backport)ClosedVictor JulienActions

Related issues 1 (0 open1 closed)

Blocked by Suricata - Bug #8206: firewall: loading rules only through yaml failsClosedVictor JulienActions
Actions

Also available in: PDF Atom