Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Development » Why not checking 802.3 packets?

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Why not checking 802.3 packets?


Posted by Dan_Lo on September 15, 2005 08:40:13

I've looked into the Snort source and figured out that Snort doesn't decode any 802.3 Ethernet packet! That is packets with length less than 1500. The problem is there are possible TCP/IP packets (network layer) tunneled in those packets. Are those packets considered as safe? If not, why Snort simply just drops them!

Also, does anybody know the header structure of network layer? The header of link layer simply contains SSAP, DSAP, and control. How to relate link layer to network layer? Thanks,