Project

General

Profile

Actions

Feature #2816

closed

vlan: support more than 2 layers

Added by Tony Gumbrell almost 6 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Protocol

Description

When running 2 x 8100 vlan tags within my data the packets are parsed neatly into the eve.json log file in the format "vlan":[123,987]. We have just added a third tag to this data and despite being able to validate the tags in pcaps, the traffic is no longer be parsed into the eve.json log at all.

Is this a system limitation or a bug?

Thanks


Related issues 1 (1 open0 closed)

Related to Suricata - Optimization #5476: decoder: compact & flexible storage of decoder data in the packetAssignedVictor JulienActions
Actions #1

Updated by Victor Julien almost 6 years ago

Currently Suricata will only deal with a max of 2 vlans per packet.

Actions #2

Updated by Tony Gumbrell almost 6 years ago

Thanks for the speedy response. Is it on the roadmap to resolve this?

Actions #3

Updated by Victor Julien almost 6 years ago

  • Tracker changed from Bug to Feature
  • Subject changed from 3 VLAN tags breaks eve.json to vlan: support more than 2 layers
  • Affected Versions deleted (4.1)

Not yet, but you're not the first to bring this up. So I think it should be addressed.

Actions #4

Updated by Andreas Herz over 5 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
Actions #5

Updated by Victor Julien over 5 years ago

  • Target version changed from TBD to 6.0.0beta1
Actions #6

Updated by Victor Julien almost 5 years ago

  • Label Protocol added
Actions #7

Updated by Victor Julien over 4 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Victor Julien
Actions #8

Updated by Victor Julien over 4 years ago

  • Target version changed from 6.0.0beta1 to 7.0.0-beta1
Actions #9

Updated by Victor Julien over 2 years ago

  • Related to Optimization #5476: decoder: compact & flexible storage of decoder data in the packet added
Actions #10

Updated by Jeff Lucovsky over 2 years ago

  • Status changed from Assigned to In Review
  • Assignee changed from Victor Julien to Jeff Lucovsky
Actions #11

Updated by Victor Julien about 2 years ago

  • Target version changed from 7.0.0-beta1 to 7.0.0-rc1
Actions #12

Updated by Victor Julien almost 2 years ago

  • Target version changed from 7.0.0-rc1 to 8.0.0-beta1
Actions #13

Updated by Jeff Lucovsky over 1 year ago

  • Status changed from In Review to Closed
Actions

Also available in: Atom PDF