snort-users January 2008 archive
Main Archive Page > Month Archives  > snort-users archives
snort-users: [Snort-users] FATAL ERROR: Cannot check flow connec

[Snort-users] FATAL ERROR: Cannot check flow connection for non-TCP traffic

From: Security Admin (NetSec) <secadmin_at_nospam>
Date: Mon Jan 28 2008 - 17:11:22 GMT
To: Snort <snort-users@lists.sourceforge.net>


I have googled for this error for a few months now (running latest 2.8.0.1) for a few weeks now, and have not found a reasonable solution to this problem. The cause appears to be in the udp rule set for just about every single udp rule across multiple rules sets. The solutions I have found thus far have been to either modify the specific rule (which could take forever depending on the # of udp rules I have to modify), disabling the udp rule (again time-consuming) or disabling the rule set entirely. I tried the third method, but with the amount of rulesets removed it left me with little to analyze.

I suspect a better solution is around, so if anyone knows and can respond, much appreciated.

FYI I am not running IpCop

Best Regards,

Edward Ray -- This mail was scanned by BitDefender For more informations please visit http://www.bitdefender.co ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users