Project

General

Profile

Actions

Feature #8334

open
VJ OD

firewall: allow matching on packet layers

Feature #8334: firewall: allow matching on packet layers

Added by Victor Julien 4 months ago. Updated 13 days ago.

Status:
Triaged
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

The firewall mode should be able to distinguish between "Ethernet/IP/TCP" and "Ethernet/VLAN/GRE/Ethernet/IP/TCP". A packet should somehow expose this to the detection engine.

Perhaps a field that holds a list of protocol id's, starting at the datalink:
DLT_EN10MB:IPV4:TCP

Perhaps this would just be string buffer, where we can match using content.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #8435: firewall: investigate handling of encapsulation/tunneling like GRE/VXLANTriagedOISF DevActions

VJ Updated by Victor Julien 3 months ago Actions #1

  • Related to Task #8435: firewall: investigate handling of encapsulation/tunneling like GRE/VXLAN added

JI Updated by Jason Ish 13 days ago Actions #2

  • Status changed from New to Triaged
  • Assignee set to OISF Dev
Actions

Also available in: PDF Atom