We are mirroring traffic to Suricata (5.0.2) via VXLAN. Our rules include detect all non-TLS and detect all UDP. We are seeing alerts for UDP VXLAN traffic.
What is the Suricata behaviour?
- Detection rules run only on decapsulated VXLAN traffic
- Detection rules run on non-decapsulated VXLAN and decapsulated VXLAN traffic
- Detection rules run only on non-decapsulated VXLAN traffic
Thanks
Zilvinas