Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: More Information Up: Tunneling Protocol Support Previous: Multiple Encapsulations   Contents

Logging

Currently, only the encapsulated part of the packet is logged, e.g.

Eth IP1 GRE IP2 TCP Payload

gets logged as

Eth IP2 TCP Payload

and

Eth IP1 IP2 TCP Payload

gets logged as

Eth IP2 TCP Payload

Note:   Decoding of PPTP, which utilizes GRE and PPP, is not currently supported on architectures that require word alignment such as SPARC.



Steven Sturges 2008-04-01