[Oisf-users] flowint br0ken ?

Edward Fjellskål edwardfjellskaal at gmail.com
Fri Dec 30 08:20:15 UTC 2011


Hi,

My flowint rules seems to have stopped working.
(Using 1.1.1)

Example:

alert ip any any -> any any (msg:"TEST SET"; flowint:test,+,1; 
classtype:not-suspicious; sid:100; rev:1;)
alert ip any any -> any any (msg:"TEST FIRE"; flowint:test,>,0; 
classtype:not-suspicious; sid:101; rev:1;)


None of them fire.

Can anyone else confirm this?

E



More information about the Oisf-users mailing list