GB_GB
(GB)
1
Hi
I’m trying to disable checking of traffic in a flow for UDP traffic.
Looking at the documentation;
this talks about TCP sessions, I assume that this does not work for UDP as when I have configured this for UDP flows, it doesn’t seem to work.
many thanks
Also I found;
From everything I could find about ‘bypass’ in a rule was it can only be used in an alert and only with TCP. Is that not correct?
This should also work for UDP…
How are you trying to bypass ?
Do you have a pcap to reproduce ?
710425820
(小酷 成(710425820))
5
This seems to be a serious problem
GB_GB
(GB)
6
Archive.zip (68.9 KB)
Please use this, it contains the rules, suricata.yaml and pcap.
thank you