diff --git a/CHANGES b/CHANGES index 27065fbece..d3133a2307 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,7 @@ +4.2.0-dev.419 | 2021-12-07 09:34:45 -0700 + + * GH-1764: Update mappings for Geneve analyzer to IP4/IP6/ARP (Tim Wojtulewicz, Corelight) + 4.2.0-dev.417 | 2021-12-06 17:00:16 -0800 * Flip C++ unit tests to being enabled by default (Christian Kreibich, Corelight) diff --git a/VERSION b/VERSION index 8fd013f893..03409e7392 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -4.2.0-dev.417 +4.2.0-dev.419 diff --git a/scripts/base/packet-protocols/geneve/main.zeek b/scripts/base/packet-protocols/geneve/main.zeek index 1131deac1d..d70055925b 100644 --- a/scripts/base/packet-protocols/geneve/main.zeek +++ b/scripts/base/packet-protocols/geneve/main.zeek @@ -19,4 +19,9 @@ event zeek_init() &priority=20 # https://datatracker.ietf.org/doc/html/draft-gross-geneve-00#section-3.4 # for details. PacketAnalyzer::register_packet_analyzer(PacketAnalyzer::ANALYZER_GENEVE, 0x6558, PacketAnalyzer::ANALYZER_ETHERNET); + + # Some additional mappings for protocols that we already handle natively. + PacketAnalyzer::register_packet_analyzer(PacketAnalyzer::ANALYZER_GENEVE, 0x0800, PacketAnalyzer::ANALYZER_IP); + PacketAnalyzer::register_packet_analyzer(PacketAnalyzer::ANALYZER_GENEVE, 0x08DD, PacketAnalyzer::ANALYZER_IP); + PacketAnalyzer::register_packet_analyzer(PacketAnalyzer::ANALYZER_GENEVE, 0x0808, PacketAnalyzer::ANALYZER_ARP); }