Snort mailing list archives

Re: Does setting HOME_NET have any effect in Stealth mode?


From: Michael Boman <michael.boman () gmail com>
Date: Tue, 2 Nov 2004 23:02:13 +0800

On Tue, 02 Nov 2004 13:05:26 +0000, Rob Ward <rob.ward () liverpool ac uk> wrote:
When I set "HOME_NET" to anything other than 'any' I no longer see any DOS
or DDOS alerts but P2P alerts are still output. I've tried following the
configuration examples in the FAQ's etc and can't get it to work. I'm
wondering if HOME_NET has any relevance when running snort in 'stealth' or
am I wide of the mark?

HOME_NET is used to define the network you are interesting to monitor,
and your snort box being in stealth mode or not has nothing to do with
it.

Also - can snort cope with variable length subnet masks?

Please explain what you mean.

Best regards
 Michael Boman


-------------------------------------------------------
This SF.Net email is sponsored by:
Sybase ASE Linux Express Edition - download now for FREE
LinuxWorld Reader's Choice Award Winner for best database on Linux.
http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: