Snort with ERSPAN

"Rajput, Jawad \(CONTR\) via Snort-devel" <[email protected]> Mon, 5 Aug 2019 12:30:04 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <SN4PR0901MB21745653BD2FD43D6202665BACDA0@SN4PR0901MB2174.namprd09.prod.outlook.com>
Good Morning,

We are trying to test Snort with ERSPAN version 1 and type 1, Snort absolutely does not detect anything. I can manually take off first 38 bytes using "editcap" utility and run the PCAP through Snort with positive hits. 

My question is, is there a way to configure/compile snort to skip first 38 bytes while inspecting a traffic? Unfortunately, I cannot share a sample PCAP per organization policy.  

Jawad Rajput, CISSP
System Administrator
U.S. Department of Energy 
IM-62 /Germantown Building
HQ Network Security Team
Email: [email protected]
Office: 301-903-2176
Office: 301-903-3895

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!