suricata: Define bypass mark

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
Tested-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
This commit is contained in:
Michael Tremer
2021-10-18 10:10:16 +00:00
committed by Arne Fitzenreiter
parent 4f07c279a0
commit 11f7218f9c
2 changed files with 4 additions and 2 deletions

View File

@@ -348,8 +348,8 @@ nfq:
mode: repeat mode: repeat
repeat-mark: 2147483648 repeat-mark: 2147483648
repeat-mask: 2147483648 repeat-mask: 2147483648
# bypass-mark: 1 bypass-mark: 1073741824
# bypass-mask: 1 bypass-mask: 1073741824
# route-queue: 2 # route-queue: 2
# batchcount: 20 # batchcount: 20
fail-open: yes fail-open: yes

View File

@@ -37,6 +37,8 @@ enabled_ips_zones=()
# Mark and Mask options. # Mark and Mask options.
REPEAT_MARK="0x80000000" REPEAT_MARK="0x80000000"
REPEAT_MASK="0x80000000" REPEAT_MASK="0x80000000"
BYPASS_MARK="0x40000000"
BYPASS_MASK="0x40000000"
# PID file of suricata. # PID file of suricata.
PID_FILE="/var/run/suricata.pid" PID_FILE="/var/run/suricata.pid"