Snort mailing list archives

logging inbound packets only


From: "njharris" <njharris () mindspring com>
Date: Sun, 2 Feb 2003 01:04:37 -0600

I have set up a second instance of snort to log packets to a mysql database.Everything works fine , except it only sees 
the 
inbound packets. The rule is "log any any any -> any any" , I even tried "log tcp $HOME_NET any -> $EXTERNAL_NET any", 
and it still only logs outbound packets. This is the only rule in the rule base. Snort.conf has been deleted of all 
others. 
My $HOME_NET 10.10.10.0/24
$EXTERNAL_NET !$HOME_NET

When the process is cancelled, snort reports that it logged all packets.

Any help is very appreciated,
Nick Harris
CTO
TNS

 


Current thread: