Snort mailing list archives
Snort 2.9 for IPv6
From: oleg gv via Snort-users <snort-users () lists snort org>
Date: Wed, 21 Feb 2018 17:17:37 +0300
Hello, I can not see alert on the next rules alert ip any any --> IPV6_ADDRESS any (...) alert icmp any any --> IPV6_ADDRESS any (...) I use ping6 to test it. Ipv4 test works fine. Snort is build with --enable-ipv6 and uses ip6tables NFQUEUE. Other ipv6 tcp/udp alerts also works fine. Is it possible to detect IPv6 addresses in ip/icmp protocol rules ?
_______________________________________________ Snort-users mailing list Snort-users () lists snort org Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
Current thread:
- Snort 2.9 for IPv6 oleg gv via Snort-users (Feb 21)
- Re: Snort 2.9 for IPv6 oleg gv via Snort-users (Feb 21)
- Re: Snort 2.9 for IPv6 Russ via Snort-users (Feb 21)
- Re: Snort 2.9 for IPv6 oleg gv via Snort-users (Feb 22)
- Re: Snort 2.9 for IPv6 oleg gv via Snort-users (Feb 22)
- Re: Snort 2.9 for IPv6 Russ via Snort-users (Feb 22)
- Re: Snort 2.9 for IPv6 Russ via Snort-users (Feb 21)
- Re: Snort 2.9 for IPv6 oleg gv via Snort-users (Feb 21)