Snort mailing list archives

Followup to HOME_NET and EXTERNAL_NET


From: "John Lathem" <jlathem () z-space com>
Date: Wed, 6 Nov 2002 10:23:16 -0500


I've changed my HOME_NET to match my IP ranges, like this:

        var HOME_NET [x.x.x.160/27,x.x.x.32/27,192.168.x.0/24]
        var EXTERNAL_NET any

This is two internet connections, plus the internal network.  However, I
still get DNS Zone Tranfers logged between my two internet interfaces.
The DNS Zone Transfer rule indicates that it would log packets from
EXTERNAL_NET to HOME_NET, but both are in HOME_NET.

When I set :

        var EXTERNAL_NET !$HOME_NET 

I don't get any alerts logged anymore, except these zone transfers.

Thanks!

---
John Lathem  <lathem () z-space com>



-------------------------------------------------------
This sf.net email is sponsored by: See the NEW Palm
Tungsten T handheld. Power & Color in a compact size!
http://ads.sourceforge.net/cgi-bin/redirect.pl?palm0001en
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: