[Oisf-users] reject-rules don't drop packages

Peter Manev petermanev at gmail.com
Tue Jan 10 10:16:38 UTC 2012

There is a bug related to inline option set to yes when reading a pcap -
that is still not closed.
I can't confirm for sure if that could be related to your set u or not.
I will try to reproduce it and get some feedback - see if i get the same


On Tue, Jan 10, 2012 at 10:56 AM, Thorsten Wagener - Travanto Travel <
twagener at travanto.de> wrote:

> Hi,
> my suricata Version 1.1.1 does not drop packages from reject rules.
> I know that there was a Bug, which was fixed in v1.1beta2 but it is still
> there. Can anyone confirm this Problem?
> Drop-rule works and bad traffic is dropped. with reject the traffic is not
> dropped, but a tcp/rst package is sent. Sometimes the rst-package is
> incoming before the answer and the connection is cancled, but the bad
> traffic is still not dropped.
> stream inline is set to yes.
> _______________________________________________
> Oisf-users mailing list
> Oisf-users at openinfosecfoundation.org
> http://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users

Peter Manev
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20120110/a3ccf934/attachment-0002.html>

More information about the Oisf-users mailing list