[Snort-devel] A "drop" rule using inline mode and NFQ mode causes an outbound network flood

Gerard Beekmans gerard at ...3293...
Fri Jun 8 14:27:57 EDT 2012


>
> I'm not sure why you see the flood.  It seems like the resets are causing
> resets, which the code looks out for.
>
> Can you send a pcap of the onset of the flood?
>


I'll send one to you directly rather than send a 2 MB attachment to
everybody on this list. If anybody else would like to look at it, let me
know.

Gerard
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-devel/attachments/20120608/e0e96bf5/attachment.html>


More information about the Snort-devel mailing list