Snort mailing list archives
Followup to HOME_NET and EXTERNAL_NET
From: "John Lathem" <jlathem () z-space com>
Date: Wed, 6 Nov 2002 10:23:16 -0500
I've changed my HOME_NET to match my IP ranges, like this: var HOME_NET [x.x.x.160/27,x.x.x.32/27,192.168.x.0/24] var EXTERNAL_NET any This is two internet connections, plus the internal network. However, I still get DNS Zone Tranfers logged between my two internet interfaces. The DNS Zone Transfer rule indicates that it would log packets from EXTERNAL_NET to HOME_NET, but both are in HOME_NET. When I set : var EXTERNAL_NET !$HOME_NET I don't get any alerts logged anymore, except these zone transfers. Thanks! --- John Lathem <lathem () z-space com> ------------------------------------------------------- This sf.net email is sponsored by: See the NEW Palm Tungsten T handheld. Power & Color in a compact size! http://ads.sourceforge.net/cgi-bin/redirect.pl?palm0001en _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Followup to HOME_NET and EXTERNAL_NET John Lathem (Nov 06)
- <Possible follow-ups>
- RE: Followup to HOME_NET and EXTERNAL_NET Don (Nov 06)