Suricata: detect TLS traffic on IMAPS/POP3S/SSMTP ports as, well

Partially fixes #11808

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Cc: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
This commit is contained in:
Peter Müller
2019-02-07 17:38:00 +00:00
committed by Stefan Schantl
parent 5fbd7b2982
commit 05a635ec04

View File

@@ -140,7 +140,7 @@ app-layer:
tls:
enabled: yes
detection-ports:
dp: 443
dp: "[443,465,993,995]"
# Completely stop processing TLS/SSL session after the handshake
# completed. If bypass is enabled this will also trigger flow