cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
327
Views
0
Helpful
2
Replies

Packet Drop - SigID: 993

muharrem
Level 1
Level 1

When I implement filtering for some hosts and tune/disable some signatures signature 993 triggers, and it says percent of packet drops is around 90%. As far as I learnt this is said to be a bug of IDS, and to be resolved with v4.0. Is any of you aware of this bug? Any reference would be appreciated.

2 Replies 2

jakasper
Level 1
Level 1

We recently found the bug with the 3.1 "Filters" (ExcludedPattern) that

had a serious performance impact.

The filters were malfunctioning and operating as pre-filters that would be examined on nearly every packet, instead of every alarm.

This is an easy fix in the code, but has not yet been released.

The last date I heard from Management was January for a 3.1 Service Pack,

following the 4.0 FCS.

-JK

Do you think it could be helpfull to change the HW platform?