[Oisf-users] rule does not always match

Vieri rentorbuy at yahoo.com
Tue Aug 22 08:44:34 UTC 2017


________________________________
From: Peter Manev <petermanev at gmail.com>
>
> Please consider upgrading to latst stable and confirm.
> Do you have a reproducible pcap you can share?


I am unable to reproduce this issue anymore, even if I do not upgrade.

I'm using Suricata "in-line" with iptables. Could it be that the undetected traffic I saw before was due to a temporary ressource issue given that I'm using NFQUEUE with "bypass"?

NFQUEUE balance 0:5 bypass

Vieri



More information about the Oisf-users mailing list