Snort mailing list archives

Snort IPv6 howto/rules


From: Stephen Reese <rsreese () gmail com>
Date: Mon, 13 Apr 2009 20:02:45 -0400

Are there any IPv6 Snort rule sets available or do they need to be
written from scratch? I've compiled Snort 2.8.4 with IPv6 support but
realized I don't a clue in regards to the configuration that's needed
to look at the IPv6 traffic. TCPDUMP on the sensor interface sees IPv6
related traffic.

Should I specify another var for the IPv6 scheme:

var HOME_NET [x.x.x.0/24,x.x.x..0/24]

IPv6 tunnel over IPv4 | Router with IPv6 address | Snort sensor |
Network with functioning IPv6 hosts

Thanks

------------------------------------------------------------------------------
This SF.net email is sponsored by:
High Quality Requirements in a Collaborative Environment.
Download a free trial of Rational Requirements Composer Now!
http://p.sf.net/sfu/www-ibm-com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: