[Snort-users] VPN traffic

Fyodor fygrave at ...121...
Wed Aug 2 17:05:01 EDT 2000


~ :alert ICMP 192.86.6.10/32 any -> any any (msg: "NS10 Outbound Traffic"; )   
~ :alert ICMP any any -> 192.86.6.10/32 any (msg: "NS10 Inbound Traffic"; ) 
~ :
~ :Two questions:
~ :
~ : - Is there a way to say "any" for the protocol?
~ :


if there's a real need in that, it could be implemented (not really sooon
though, I've got around 4 snort-related tasks pending in my todo list:)) 





More information about the Snort-users mailing list