Home page logo

snort logo Snort mailing list archives

(snort_decoder) WARNING: IP dgm len > captured len!
From: Martin Roecker <roecker () linogate de>
Date: Tue, 12 Oct 2010 11:39:36 +0200


since were running snort in version 2.9.0 packets with a
bigger size than 1369 bytes are droped by snort. This happens
when we run snort in inline mode using the ipq daq.

When I start snort in sniffer mode with the pcap daq, I can see
a message "(snort_decoder) WARNING: IP dgm len > captured len!"

Can you tell me what to do to get rid of this message?

Using "config enable_decode_oversized_alerts" in snort.conf as I found
here [1] did not help...



Beautiful is writing same markup. Internet Explorer 9 supports
standards for HTML5, CSS3, SVG 1.1,  ECMAScript5, and DOM L2 & L3.
Spend less time writing and  rewriting code and more time creating great
experiences on the web. Be a part of the beta today.
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]