Supported protocols and inspection capabilities of LINA and Snort 3
LINA
LINA supports decoding for the following protocols across the Data Link (L2), Network (L3), and Transport (L4) layers.
|
Layer |
Supported protocols and headers |
|---|---|
|
Layer 2 |
Cisco MetaData (CMD), IEEE 802.1Q, IEEE 802.1ad (DOT1AD), and Q-in-Q (EtherTypes 0x9100 and 0x9200). Supports up to three levels of VLAN headers. |
|
Layer 3 |
IPv4, IPv6 |
|
Layer 4 |
ICMP (v4/v6), ESP, VXLAN, Geneve, GRE, IP-in-IP, and IPv6-in-IPv6. Supports up to 1 level of encapsulation. |
GRE-specific support
For GRE traffic, the system supports decoding for the following protocol types:
-
Point-to-Point Tunneling Protocol (PPTP)
-
Web Cache Communication Protocol (WCCP)
ERSPAN handling
The system decodes GRE and ERSPAN (types 1, 2, and 3). To facilitate dispatch layer load-balancing, the system internally skips to the inner headers. Consequently, other modules are unable to inspect ERSPAN headers.
Snort 3
While Snort 3 supports a vast array of protocols, the following list highlights common encapsulation and tunneling protocols supported for inspection:
-
VXLAN
-
GRE
-
Teredo
-
GTP
-
MPLS
-
Geneve
-
IP-in-IP
-
IPv4-in-IPv4
-
IPv6-in-IPv4
-
IPv4-in-IPv6
-
IPv6-in-IPv6
-
Note | This list is not exhaustive. Snort 3 is designed to decode a wide range of industry-standard protocols. |