Snort mailing list archives
Addressing in rules
From: Chris Garringer <chris.garringer () tic toshiba com>
Date: 11 Mar 2003 11:18:46 -0600
Is there a way to tell snort , any address but x? I have rule using $EXTERNAL_NET that is firing for a known address of mine (internal host). I tried [!xx.xx.xx.xx,$EXTERNAL_NET] as the source address. Snort starts fine, does not complain, but still has the alerts firing. Is there a way to do this? -- Chris D. Garringer Toshiba International LAN/WAN Supervisor 713-466-0277 x3756 Certified Solaris Administrator Microsoft Certified Engineer (NT) RedHat Certified Engineer ------------------------------------------------------- This SF.net email is sponsored by:Crypto Challenge is now open! Get cracking and register here for some mind boggling fun and the chance of winning an Apple iPod: http://ads.sourceforge.net/cgi-bin/redirect.pl?thaw0031en _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Addressing in rules Chris Garringer (Mar 11)
- Re: Addressing in rules Erek Adams (Mar 11)
