SURICATA UDPv6 invalid checksum



  • I am getting loads of blocks in Suricata,

    06/16/2018-20:24:09.762839  [Block Dst] [**] [1:2200078:2] SURICATA UDPv6 invalid checksum [**] [Classification: Generic Protocol Command Decode] [Priority: 3]
    

    I have enabled "Disable hardware checksum offload" in Advanced>Networking>Hardware Checksum Offloading which seems to have gotten rid of "SURICATA UDPv4 invalid checksum". But this IPV6 checksum still comes up.

    My system is Supermicro A2SDi-4C-HLN4F running Intel X553 nics.



  • @trumee
    I think we ended disabling the entire stream-events.rules ruleset to avoid these errors. IIRC if you are in legacy mode the packets can be scanned out of order and trigger false positives.


Log in to reply