mirror of
https://github.com/zeek/zeek.git
synced 2025-10-16 21:48:21 +00:00

Loading policy/protocols/conntuple/vlan adapts Zeek's flow hashing and the script-layer conn_id record to show VLAN tags when present. I'm using script-layer ints for the VLAN tag representation for consistency with what we alrady do elsewhere, but it seems odd since they can never be negative. I'm currently skipping protocols/conntuple/vlan in test-all-policy since it otherwise affects the external testsuites -- could revisit if people feel it should run on these.
8 lines
437 B
Text
8 lines
437 B
Text
# @TEST-DOC: Verifies that the VLAN-aware conntuple builder correctly distinguishes colliding 5-tuples that only differ in their vlan tagging.
|
|
#
|
|
# @TEST-EXEC: zeek -b -r $TRACES/conntuple/tuple-collision-vlan.pcap %INPUT
|
|
# @TEST-EXEC: zeek-cut -m ts uid id.orig_h id.orig_p id.resp_h id.resp_p id.vlan id.inner_vlan <conn.log >conn.log.cut
|
|
# @TEST-EXEC: btest-diff conn.log.cut
|
|
|
|
@load base/protocols/conn
|
|
@load protocols/conntuple/vlan
|