Project

General

Profile

Actions

Feature #507

closed

Implement/test "fail-open" option

Added by Eric Leblond over 12 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

A new feature has recently been introduced in NFQUEUE. It is possible to accept packets when the queue is full. This could be useful in Suricata when admin wants to privilege network behavior over security.

More information and patch: http://www.digipedia.pl/usenet/thread/16261/26536/


Files

Actions

Also available in: Atom PDF