Snort mailing list archives

HOME_NET Clarification


From: Ilango S Allikuzhi <IlangoAllikuzhi () dtcc com>
Date: Fri, 22 Oct 2004 12:24:55 -0400

Is it possible to define HOME_NET as [!10.40.1.0/24, !10.40.2.0/24, 
10.0.0.0/8, 192.168.1.0/24]  for instance?
In other words, we want all subnets under 10 except a few.
Some public addresses get NAT'ed to 10.40.2.x addresses and hence I need 
to treat them as external net. 
Thanks,
Ilango


Current thread: