<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to suppress INVALID CONTENT-LENGTH OR CHUNK SIZE]]></title><description><![CDATA[<p dir="auto">I am constantly getting these in Snort Alerts.  Is it ok to suppress these for my ISP's address?  What is the code to supress this kind of http_inspect?</p>
<p dir="auto">WAN Jul 09 06:45:39 my.isp.my.isp:8644    (http_inspect) INVALID CONTENT-LENGTH OR CHUNK SIZE<br />
                                      62.119.66.46:80</p>
<p dir="auto">I think that it should be something like:<br />
suppress gen_id 120, sig_id 2, track by_src, ip my.isp.my.isp</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/topic/102627/how-to-suppress-invalid-content-length-or-chunk-size</link><generator>RSS for Node</generator><lastBuildDate>Mon, 16 Mar 2026 02:50:22 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/102627.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 10 Jul 2016 14:32:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to suppress INVALID CONTENT-LENGTH OR CHUNK SIZE on Mon, 11 Jul 2016 14:29:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/battles">@<bdi>battles</bdi></a>:</p>
<blockquote>
<p dir="auto">Thanks.  I was trying to individually suppress a rule for my isp address in Services / Snort / Alerts, and upon clicking the + button, I got this error:</p>
<p dir="auto">The following input errors were detected:<br />
Suppress List 'wansuppress_57828044c1f52' is defined for this interface, but it could not be found!</p>
<p dir="auto">Wonder what this is about?</p>
</blockquote>
<p dir="auto">Maybe a previously created/assigned suppress list that was later deleted.  Go to the INTERFACE SETTINGS tab for the Snort interface and set the SUPPRESS LIST to "default" and save the change.  Now go back to the ALERTS tab and try the suppress action again.  When you click the suppress icon on the ALERTS tab, it will auto-create a Suppress List file for the interface and assign it if one does not already exist.  If one is defined in the <em>config.xml</em>, then it will use that one instead.  In your case, one was defined in the <em>config.xml</em> for the interface but the actual content was not in the <em>config.xml</em> file.  This usually means the old list was deleted.</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/636854</link><guid isPermaLink="true">https://forum.netgate.com/post/636854</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Mon, 11 Jul 2016 14:29:35 GMT</pubDate></item><item><title><![CDATA[Reply to How to suppress INVALID CONTENT-LENGTH OR CHUNK SIZE on Mon, 11 Jul 2016 14:17:32 GMT]]></title><description><![CDATA[<p dir="auto">Thanks.  I was trying to individually suppress a rule for my isp address in Services / Snort / Alerts, and upon clicking the + button, I got this error:</p>
<p dir="auto">The following input errors were detected:<br />
Suppress List 'wansuppress_57828044c1f52' is defined for this interface, but it could not be found!</p>
<p dir="auto">Wonder what this is about?</p>
]]></description><link>https://forum.netgate.com/post/636846</link><guid isPermaLink="true">https://forum.netgate.com/post/636846</guid><dc:creator><![CDATA[battles]]></dc:creator><pubDate>Mon, 11 Jul 2016 14:17:32 GMT</pubDate></item><item><title><![CDATA[Reply to How to suppress INVALID CONTENT-LENGTH OR CHUNK SIZE on Mon, 11 Jul 2016 00:28:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/battles">@<bdi>battles</bdi></a>:</p>
<blockquote>
<p dir="auto">Finally figured this out: Service / Snort / Alerts / click + next to rule to suppress.</p>
</blockquote>
<p dir="auto">Yuo got it.  You can also just completely disable that rule.  I think a lot of folks disable quite a number of the HTTP_INSEPCT preprocessor rules as they tend to alert on just about every tiny infraction of RFC specs.  To disable a rule on the ALERTS tab, click the red <strong>X</strong> icon located beside the GID:SID.</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/636759</link><guid isPermaLink="true">https://forum.netgate.com/post/636759</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Mon, 11 Jul 2016 00:28:12 GMT</pubDate></item><item><title><![CDATA[Reply to How to suppress INVALID CONTENT-LENGTH OR CHUNK SIZE on Sun, 10 Jul 2016 17:04:23 GMT]]></title><description><![CDATA[<p dir="auto">Finally figured this out: Service / Snort / Alerts / click + next to rule to suppress.</p>
]]></description><link>https://forum.netgate.com/post/636725</link><guid isPermaLink="true">https://forum.netgate.com/post/636725</guid><dc:creator><![CDATA[battles]]></dc:creator><pubDate>Sun, 10 Jul 2016 17:04:23 GMT</pubDate></item></channel></rss>