Snort mailing list archives

Re: Maybe a bit OT...


From: "J. Craig Woods" <drjung () sprynet com>
Date: Sat, 23 Feb 2002 14:20:05 -0600

John Sage wrote:

Craig:

I think you want /16, if you want the whole block:

Address:   4.41.0.0              00000100.00101001 .00000000.00000000
Netmask:   255.255.0.0 == 16     11111111.11111111 .00000000.00000000
=>
Network:   4.41.0.0/16           00000100.00101001 .00000000.00000000 (Class A)
Broadcast: 4.41.255.255          00000100.00101001 .11111111.11111111
HostMin:   4.41.0.1              00000100.00101001 .00000000.00000001
HostMax:   4.41.255.254          00000100.00101001 .11111111.11111110
Hosts/Net: 65534

(Cool tool tip: ipcalc @ http://jodies.cx/ipcalc.pl )

What about this is *not* working?

The netblock range, or something else?


Thanks to all that helped, especially for the very cool tool. You guys
were right, it was "4.41.0.0/16 that I wanted to filter out. Seems it
was not doing its thing because of where I put the rule in reference to
the other ipchains rules. Just like in snort, it makes a difference. 

Thanks,
-- 
J. Craig Woods
UNIX/NT Network/System Administration

-Art is the illusion of spontaneity-

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: