Project

General

Profile

Actions

Task #8435

open

firewall: investigate handling of encapsulation/tunneling like GRE/VXLAN

Added by Victor Julien about 18 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Target version:
Effort:
Difficulty:
Label:

Description

These packets lead to several internal packets that are connected for the verdict. The rule language is not aware of this though.

First step would be to create a test for these cases:
  • VXLAN
  • Geneve
  • GRE
  • IP in IP
  • etc

We may want to disallow things like IP in IP globally or in a ruleset.


Related issues 2 (2 open0 closed)

Related to Suricata - Feature #8334: firewall: allow matching on packet layersNewActions
Related to Suricata - Task #7269: firewall: comprehensive rules testsIn ProgressVictor JulienActions
Actions

Also available in: Atom PDF