[Snort-users] Exclude IP addresses for all rules

James-lists hackerwacker at ...3784...
Sun Dec 15 20:50:06 EST 2002


try:

var HOME_NET
[!$EXCLUDE,192.168.1.0/32,192.168.1.3/32,192.168.1.4/30,192.168.1.8/29,1
92.168.16/28,192.168.32/27,192.168.64/26\
192.168.128/25]

I think my bit boundaries are correct, but YMMV. This variable
configuration will add more processor load to Snort.





More information about the Snort-users mailing list