Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Linux » Error: TCP loss

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Error: TCP loss


Posted by wjhu on October 10, 2006 21:51:02

When i ran anort on a 64-bit OS, snort loss many tcp ,while it can caught most udp packet.
-------------------------------------------------------------------------------
rules:
alert tcp any any <> any any
snort ran:
===============================================================================

Snort received 360 packets
Analyzed: 178(49.444%)
Dropped: 0(0.000%)
Outstanding: 182(50.556%)
===============================================================================
Breakdown by protocol:
TCP: 42 (23.596%)
UDP: 59 (33.146%)
ICMP: 1 (0.562%)
ARP: 60 (33.708%)
EAPOL: 0 (0.000%)
IPv6: 0 (0.000%)
ETHLOOP: 3 (1.685%)
IPX: 0 (0.000%)
FRAG: 0 (0.000%)
OTHER: 13 (7.303%)
DISCARD: 0 (0.000%)
===============================================================================
Action Stats:
ALERTS: 0
LOGGED: 0
PASSED: 0
===============================================================================







Is it a bug????


Posted by wjhu on October 10, 2006 21:53:51

rules:
alert udp any any <> any any

snort ran:
===============================================================================

Snort received 150 packets
Analyzed: 73(48.667%)
Dropped: 0(0.000%)
Outstanding: 77(51.333%)
===============================================================================
Breakdown by protocol:
TCP: 11 (15.068%)
UDP: 20 (27.397%)
ICMP: 0 (0.000%)
ARP: 35 (47.945%)
EAPOL: 0 (0.000%)
IPv6: 0 (0.000%)
ETHLOOP: 1 (1.370%)
IPX: 0 (0.000%)
FRAG: 0 (0.000%)
OTHER: 6 (8.219%)
DISCARD: 0 (0.000%)
===============================================================================
Action Stats:
ALERTS: 20
LOGGED: 20
PASSED: 0
===============================================================================