Re: IPV six

Jonathan Lee via Snort-users <[email protected]> Fri, 3 Oct 2025 07:52:19 -0700
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
--===============6276125308642008398==
Content-Type: multipart/alternative; boundary=Apple-Mail-822714C1-D052-481D-B6EE-95588773688A
Content-Transfer-Encoding: 7bit


--Apple-Mail-822714C1-D052-481D-B6EE-95588773688A
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hello all is there anything I should check I only see one or two a week righ=
t now=20
Sent from my iPhone

> On Sep 30, 2025, at 07:26, Jonathan Lee <[email protected]> wrote:
>=20
> =EF=BB=BF
> Hi,
>=20
> I'm observing some IPv6 activity being detected, but IPv4 traffic is signi=
ficantly more prevalent. Is there anything in particular I should be investi=
gating on this front?
>=20
> IPv6 traffic does appear when app ID-related activity is detected, but in t=
erms of potential threats=E2=80=94especially from the perspective of invasiv=
e actors and official Snort signatures=E2=80=94I'm not seeing many relevant d=
etections tied to IPv6.
>=20
> Thanks!
>=20
> Sent from my iPhone

--Apple-Mail-822714C1-D052-481D-B6EE-95588773688A
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi=
v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D=
"auto">Hello all is there anything I should check I only see one or two a we=
ek right now&nbsp;<br id=3D"lineBreakAtBeginningOfSignature"><div dir=3D"ltr=
">Sent from my iPhone</div><div dir=3D"ltr"><br><blockquote type=3D"cite">On=
 Sep 30, 2025, at 07:26, Jonathan Lee &lt;[email protected]&gt; wrote=
:<br><br></blockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=
=BF<meta http-equiv=3D"content-type" content=3D"text/html; charset=3Dutf-8">=
<p data-start=3D"77" data-end=3D"84" style=3D"-webkit-text-size-adjust: auto=
;"><strong data-start=3D"77" data-end=3D"84">Hi,</strong></p><p data-start=3D=
"86" data-end=3D"258" style=3D"-webkit-text-size-adjust: auto;">I'm observin=
g some IPv6 activity being detected, but IPv4 traffic is significantly more p=
revalent. Is there anything in particular I should be investigating on this f=
ront?</p><p data-start=3D"260" data-end=3D"497" style=3D"-webkit-text-size-a=
djust: auto;">IPv6 traffic does appear when app ID-related activity is detec=
ted, but in terms of potential threats=E2=80=94especially from the perspecti=
ve of invasive actors and official Snort signatures=E2=80=94I'm not seeing m=
any relevant detections tied to IPv6.</p><p data-start=3D"499" data-end=3D"5=
06" style=3D"-webkit-text-size-adjust: auto;">Thanks!</p><div dir=3D"ltr">Se=
nt from my iPhone</div></div></blockquote></body></html>=

--Apple-Mail-822714C1-D052-481D-B6EE-95588773688A--

--===============6276125308642008398==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============6276125308642008398==--