[Snort-users] IP Address's in Rule

Slighter, Tim tslighter at ...5174...
Wed Oct 9 10:41:05 EDT 2002

if you only wish to exclude those specific IP addresses, then you should not
need the $EXTERNAL_NET as it will alert for anything but the !x.x.x.x/32
-----Original Message-----
From: Mike McCabe [mailto:mike at ...6998...]
Sent: Wednesday, October 09, 2002 10:57 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] IP Address's in Rule

How do I include specific IP addresses in a rule.  Say I want to have
certain IP addresses not looked at and still want the rule to use
EXTERNAL_NET...  Something like:

alert tcp [!X.Y.W.Z/32,!A.B.C.D/32,!E.F.G.H/32,$EXTERNAL_NET] any ->
$HOME_NET 53 (msg:"DNS zone transfer"; content: "|00 00 FC|"; flags: A+;
offset: 13; reference:arachnids,212; classtype:attempted-recon; sid:255;

But it doesn't seem to work...

Any help would be appreciated...


This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-users mailing list