Snort mailing list archives

$HOME_NET and $EXTERNAL_NET configuration problem


From: Marco Stolpe <x25ugip1 () freenet de>
Date: Thu, 11 Sep 2003 15:23:07 +0200

Hello,

I'm using Snort on my OpenBSD firewall machine, although I know that it was better to use seperate machines for that task. But at the moment I cannot afford any new PCs and I think for a small home network like mine it would be overkill anyhow.

My setup looks like the following:

Internet <-> DSL-Router <-> rl0 FW rl1 <-> Private Network

DSL-Router (IP): 192.168.1.1
FW (IP on rl0):  192.168.1.2
FW (IP on rl1):  192.168.54.1

So I have two networks, one before my firewall (192.168.1.0/24) and one behind (192.168.54.0/24).

I wish to run an instance of Snort on each interface (rl0 and rl1) to know better what attacks are tried on the external interface, which of those attacks are getting blocked by the firewall and if any attacks were able to enter my internal network. But at the same time, I'd like to do the same for the other direction - internal network to internet - in case malicious software got installed and tries to contact it's home servers or to spread further across the internet.

Now I'm somewhat confused about the variables $EXTERNAL_NET and $HOME_NET.

If I want to control traffic in *both* directions, do I have to set those variables both to "any"?

I read something like this in the FAQ, but would like to be sure that this is the right way to do it for the setup I've shown above.

Many greetings,

Marco



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: