[Snort-devel] EDNS-Client-Subnet ECS

Da Pozzo Matteo m.dapozzo at ...3663...
Thu Mar 16 05:34:35 EDT 2017


I would like if there is any plan for development regarding EDNS-Client-Subnet (like field extraction for Original-client-IP for HTTP) . I think that It could be useful for security purposes in existing deployments in order to use DNS query content like XFF for HTTP.

Please, let me know about your opinion.

Thanks in advance,

Best Regards.


Matteo Da Pozzo

Communication Valley
Via Robert Koch, 1/4
20152 - Milano - ITALY
phone: +39 02 535761
mobile: +39 345 4954311
m.dapozzo at ...3663...<mailto:m.dapozzo at ...3663...>

[Communication Valley]


The information transmitted is intended for the person or entity to which it is addressed and may contain confidential and/or privileged material. Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon, this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender and delete the material from any computer.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-devel/attachments/20170316/005ee3dd/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: com_valley.png
Type: image/png
Size: 3145 bytes
Desc: com_valley.png
URL: <https://lists.snort.org/pipermail/snort-devel/attachments/20170316/005ee3dd/attachment.png>

More information about the Snort-devel mailing list