Snort mailing list archives

Re: HOME_NET, EXTERNAL_NET, ipvar unwanted triggered rules


From: "Al Lewis (allewi)" <allewi () cisco com>
Date: Fri, 9 Jun 2017 16:39:20 +0000

Hello,

        Do you have any example traffic?

Albert Lewis
ENGINEER.SOFTWARE ENGINEERING
SOURCEfire, Inc. now part of Cisco
Email: allewi () cisco com 








On 6/9/17, 12:32 PM, "David Smith" <DSmith () smhcems org> wrote:

Members,

ENV: Ubuntu 16.04, Snort V 2.9.9.0, Barnyard2 V 2.1.14, PulledPork 0.7.3, BASE 1.4.5


Snort rules, pulled in from PulledPork are being triggered from addresses within the defined HOME_NET as if they are 
part of the EXTERNAL_NET, which is causing unwanted alerts.

Snort.conf:
ipvar HOME_NET [192.168.1.0/24,192.168.3.0/24]
ipvar EXTERNAL_NET !$HOME_NET

Rule example:
alert tcp $EXTERNAL_NET any -> $HOME_NET 53.........

Can't find anything in docs or web that has solved this issue for me.    Thoughts or ideas?

Thanks!

Dave Smith

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: