Supported protocols and inspection capabilities of LINA and Snort 3

LINA

LINA supports decoding for the following protocols across the Data Link (L2), Network (L3), and Transport (L4) layers.

Layer

Supported protocols and headers

Layer 2

Cisco MetaData (CMD), IEEE 802.1Q, IEEE 802.1ad (DOT1AD), and Q-in-Q (EtherTypes 0x9100 and 0x9200). Supports up to three levels of VLAN headers.

Layer 3

IPv4, IPv6

Layer 4

ICMP (v4/v6), ESP, VXLAN, Geneve, GRE, IP-in-IP, and IPv6-in-IPv6. Supports up to 1 level of encapsulation.

GRE-specific support

For GRE traffic, the system supports decoding for the following protocol types:

  • Point-to-Point Tunneling Protocol (PPTP)

  • Web Cache Communication Protocol (WCCP)

ERSPAN handling

The system decodes GRE and ERSPAN (types 1, 2, and 3). To facilitate dispatch layer load-balancing, the system internally skips to the inner headers. Consequently, other modules are unable to inspect ERSPAN headers.

Snort 3

While Snort 3 supports a vast array of protocols, the following list highlights common encapsulation and tunneling protocols supported for inspection:

  • VXLAN

  • GRE

  • Teredo

  • GTP

  • MPLS

  • Geneve

  • IP-in-IP

    • IPv4-in-IPv4

    • IPv6-in-IPv4

    • IPv4-in-IPv6

    • IPv6-in-IPv6

Note

This list is not exhaustive. Snort 3 is designed to decode a wide range of industry-standard protocols.