Project

General

Profile

Actions

Feature #5468

closed

Task #4773: research: IPS behavior wrt resource limits

ips: midstream: add "exception policy" for midstream

Added by Victor Julien over 2 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:
Needs backport to 6.0

Description

Allow a policy to specified for midstream connections. This should include the typical fail open to fail closed options.

A grace period after startup may need to be part of this, so that a sensor restart doesn't automatically apply to all open connections right way. The grace period should also be allowed to 0 (disabled).


Subtasks 1 (0 open1 closed)

Feature #5500: ips: midstream: add "exception policy" for midstream (6.0.x backport)ClosedJuliana Fajardini ReichowActions

Related issues 2 (1 open1 closed)

Related to Suricata - Feature #5469: rules: expose per flow stream.midstream setting to the rule languageNewOISF DevActions
Copied to Suricata - Feature #5500: ips: midstream: add "exception policy" for midstream (6.0.x backport)ClosedJuliana Fajardini ReichowActions
Actions #1

Updated by Victor Julien over 2 years ago

  • Description updated (diff)
Actions #2

Updated by Victor Julien over 2 years ago

  • Related to Feature #5469: rules: expose per flow stream.midstream setting to the rule language added
Actions #3

Updated by Juliana Fajardini Reichow over 2 years ago

  • Subtask #5495 added
Actions #4

Updated by Juliana Fajardini Reichow over 2 years ago

  • Assignee changed from OISF Dev to Juliana Fajardini Reichow
Actions #5

Updated by Juliana Fajardini Reichow over 2 years ago

  • Status changed from New to In Progress
Actions #6

Updated by Juliana Fajardini Reichow over 2 years ago

  • Label Needs backport to 6.0 added

First PR for review https://github.com/OISF/suricata/pull/7727

starting to work on documentation now.

Actions #7

Updated by Juliana Fajardini Reichow over 2 years ago

  • Copied to Feature #5500: ips: midstream: add "exception policy" for midstream (6.0.x backport) added
Actions #8

Updated by Juliana Fajardini Reichow over 2 years ago

  • Subtask #5500 added
Actions #9

Updated by Juliana Fajardini Reichow over 2 years ago

  • Status changed from In Progress to In Review
Actions #10

Updated by Juliana Fajardini Reichow over 2 years ago

  • Status changed from In Review to Resolved
Actions #11

Updated by Victor Julien over 2 years ago

  • Target version changed from TBD to 7.0.0-beta1
Actions #12

Updated by Victor Julien over 2 years ago

  • Subtask deleted (#5495)
Actions #13

Updated by Victor Julien over 2 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF