pfsense:suricata:alerts:suricata_udpv4_invalid_checksum
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pfsense:suricata:alerts:suricata_udpv4_invalid_checksum [2020/03/01 18:05] – removed peter | pfsense:suricata:alerts:suricata_udpv4_invalid_checksum [2021/01/14 17:17] (current) – peter | ||
---|---|---|---|
Line 1: | Line 1: | ||
+ | ====== PFSense - Suricata - Alerts - SURICATA UDPv4 invalid checksum ====== | ||
+ | |||
+ | Disable Hardware Checksum Offloading under **System -> Advanced -> Networking**. | ||
+ | |||
+ | ---- | ||
+ | |||
+ | ===== Suppress ===== | ||
+ | |||
+ | < | ||
+ | #SURICATA UDPv4 invalid checksum | ||
+ | suppress gen_id 1, sig_id 2200075 | ||
+ | </ | ||
+ | |||
+ | ---- | ||
+ | |||
+ | <WRAP info> | ||
+ | **NOTE: | ||
+ | |||
+ | If that does not do it, you can simply disable this particular rule by either clicking the red X icon on the **Alerts** tab in the GID/SID column, or you can find and selectively disable that rule on the **Rules** tab for the interface. | ||
+ | |||
+ | See this thread from the official Suricata documentation Wiki for details: | ||
+ | |||
+ | * http:// | ||
+ | |||
+ | Suricata uses PCAP for packet capture during Legacy Blocking Mode operation, and Netmap for Inline IPS Mode operation. | ||
+ | |||
+ | In both cases, hardware checksum offloading needs to be disabled. | ||
+ | </ | ||
pfsense/suricata/alerts/suricata_udpv4_invalid_checksum.1583085943.txt.gz · Last modified: 2020/07/15 09:30 (external edit)