[Snort-users] Question about ip_flags field

Pablo Castillo pcastillo at ...453...
Fri Jan 26 10:28:29 EST 2001


Hi everyone,

I'm completely lost with this, please help! :-)

Why the database plugin only inserts the MF bit of the ip flags in the
field "ip_flags"?

And, if the plugin do not log fragments, what is the purpose of this
field.

Thanks in advance.






More information about the Snort-users mailing list