[Snort-users] VPN traffic

Bill Pennington billp at ...60...
Wed Aug 2 17:28:00 EDT 2000


I would vote for an any option. There are times when I want to watch
everything from or to a certain place.

Fyodor wrote:
> 
> ~ :alert ICMP 192.86.6.10/32 any -> any any (msg: "NS10 Outbound Traffic"; )
> ~ :alert ICMP any any -> 192.86.6.10/32 any (msg: "NS10 Inbound Traffic"; )
> ~ :
> ~ :Two questions:
> ~ :
> ~ : - Is there a way to say "any" for the protocol?
> ~ :
> 
> if there's a real need in that, it could be implemented (not really sooon
> though, I've got around 4 snort-related tasks pending in my todo list:))
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> http://lists.sourceforge.net/mailman/listinfo/snort-users

-- 


Bill Pennington
Senior IT Manager
Rocketcash
billp at ...60...
http://www.rocketcash.com




More information about the Snort-users mailing list