[Snort-users] VPN traffic
fygrave at ...121...
Wed Aug 2 17:05:01 EDT 2000
~ :alert ICMP 220.127.116.11/32 any -> any any (msg: "NS10 Outbound Traffic"; )
~ :alert ICMP any any -> 18.104.22.168/32 any (msg: "NS10 Inbound Traffic"; )
~ :Two questions:
~ : - Is there a way to say "any" for the protocol?
if there's a real need in that, it could be implemented (not really sooon
though, I've got around 4 snort-related tasks pending in my todo list:))
More information about the Snort-users