Snort mailing list archives
Re: Modifying Rules Works One Direction, but Not T'Other
From: Doug Burks <doug.burks () gmail com>
Date: Sat, 29 Nov 2014 19:04:07 -0500
Replies inline. On Sat, Nov 29, 2014 at 6:35 PM, colony.three <colony.three () protonmail ch> wrote:
On Sat, Nov 29, 2014 at 3:22 PM, colony.three wrote:These variables are not defined in the bash environment and that's why your tests are showing up blank. These variables are defined in your snort.conf file. Please see /etc/nsm/HOSTNAME-INTERFACE/snort.conf. In that case the rule-update script can not work correctly.Why do you say that?In order for the script to invoke the rule modifications I've made, it has to know which IPs are local and which are not. It does not know this.
No, rule-update just runs PulledPork and it does not need to know what these variables are.
I noticed /etc/nsm/hex-eth0/snort.conf, but I couldn't find anywhere in the documentation nor videos where it says I need to modify that for my network.Please see Step #1 on the PostInstallation page on our Wiki:https://code.google.com/p/security-onion/wiki/PostInstallation Ok I see. Looks like I never made it to this page.And it doesn't define EXTERNAL_NET correctly anyway; It sets it to 'any', when it should be !$HOME_NET.Some organizations want/need EXTERNAL_NET to be 'any'.Also note that Snort's default snort.conf has EXTERNAL_NET set to 'any':https://labs.snort.org/snort/2970/snort.confYou can certainly set it to !$HOME_NET if that's what you'd like to do.Suggestion to all: Doesn't make sense to set EXTERNAL_NET=any.
That may be true for your environment. But there are environments where EXTERNAL_NET=any makes sense. Not all environments are the same. That's why it's a variable, so that folks can modify it to suit their environment.
And anyway, I have reason to doubt it is noticed by SO.If HOME_NET and EXTERNAL_NET are defined properly in the correctsnort.conf file, then Snort will read those variables correctly. I will take your word for it Doug, although I have no other evidence. Apparently there's some kind of magick going on.This Snort mailing list is public and is therefore indexed by Google,so there's really not much difference between exposing your email address to this Snort mailing list or the Security Onion mailing list. Suffice it to say that there is a difference in class with G**gle, between 'external sources' and 'internal sources'. Clearly Doug, you are all about G**gle. But you've made a fine product, and it is not my place to proselytize about G**gle to you. But some day you will know.
I fully understand the concerns that folks have about Google. I'll repeat my previous statement that you sending an email to this Snort mailing list is still public info and still indexed by Google. If you have further questions about Security Onion, please send an email to security-onion () googlegroups com and, again, you can use your existing email account. -- Doug Burks Need Security Onion Training or Commercial Support? http://securityonionsolutions.com Last day to register for 3-Day Training Class in Augusta GA is 12/11! ------------------------------------------------------------------------------ Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server from Actuate! Instantly Supercharge Your Business Reports and Dashboards with Interactivity, Sharing, Native Excel Exports, App Integration & more Get technology previously reserved for billion-dollar corporations, FREE http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Re: Modifying Rules Works One Direction, but Not T'Other, (continued)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other Joel Esler (jesler) (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other Doug Burks (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other Doug Burks (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other Doug Burks (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other Doug Burks (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other Doug Burks (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other Joel Esler (jesler) (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 29)
- Re: Modifying Rules Works One Direction, but Not T'Other Doug Burks (Nov 30)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 30)
- Re: Modifying Rules Works One Direction, but Not T'Other colony.three (Nov 29)