[Snort-users] Snort3: no rule for "bad cksum"

Meridoff oagvozd at gmail.com
Wed Mar 27 05:26:25 EDT 2019


Hello, I 've set up in network {}  table all options concerning cksum
evaluating and bad cksum dropping. All is ok - bad cksum packet is not
forwarded through snort.

But now messeges in log about it. And I've not found any rule for bad cksum
in builtin rules.

Why? And how I can recognize that packet with bad cksum was alerted/dropped
and so on ?

Thanks!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20190327/dba72fa8/attachment.html>


More information about the Snort-users mailing list