Project

General

Profile

Actions

Bug #8951

closed
LS LS

engine-analysis: packet:filter policy is hardcoded to drop:packet

Bug #8951: engine-analysis: packet:filter policy is hardcoded to drop:packet

Added by Lukas Sismis 21 days ago. Updated 8 days ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

FirewallAnalyzer() writes a fixed "drop:packet" for the packet:filter table instead of the policy that was actually resolved from the config.

The runtime uses fw_policies->pkt[DETECT_FIREWALL_POLICY_PACKET_FILTER] (detect.c, DetectRunSetup), which DetectFirewallLoadPacketPolicy() fills in from firewall.policies.packet.filter, packet.default-policy or the global default-policy.

The app tables are fine, AddPolicy() renders the real value for those. Only the packet table is hardcoded.


Subtasks 1 (0 open1 closed)

Bug #8952: engine-analysis: packet:filter policy is hardcoded to drop:packet (8.0.x backport)ClosedLukas SismisActions

OT Updated by OISF Ticketbot 21 days ago Actions #1

  • Subtask #8952 added

OT Updated by OISF Ticketbot 21 days ago Actions #2

  • Label deleted (Needs backport to 8.0)

LS Updated by Lukas Sismis 19 days ago Actions #3

  • Status changed from In Progress to In Review

VJ Updated by Victor Julien 11 days ago Actions #4

  • Status changed from In Review to Resolved

VJ Updated by Victor Julien 8 days ago Actions #5

  • Status changed from Resolved to Closed
Actions

Also available in: PDF Atom