Project

General

Profile

Actions

Feature #957

closed

reject: iface setup

Added by Eric Leblond about 11 years ago. Updated about 11 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

When libnet is used to send a reject message, there is currently no choosen interface. In sniffing mode, this result on the packet being sent to the routing interface which is not the attended behavior.

A fix is to add a suri-is-router YAML variable. If set to yes, then we keep the system unchanged. If set to no, then we sent the RST packet on the interface the packet comes from. If set to auto (default) we are setting internally the variable to yes in IPS mode and no in IDS mode.

Actions

Also available in: Atom PDF