[Snort-users] single IP icmp alert rule error

Thu Jan 30 06:52:07 EST 2003

OK ... this should be simple... please forgive this lowly novice's ignorance

I created a simple rule in the icmp_info rule folder

(more or less)
alert icmp any any -> $HOME_NET any (msg:"test of ping";)

I then issued a ping from a remote machine against ..
This worked fine.  The log reported the alert.

I then changed this rule to alert when pings were being issued from
I changed the above rule to..

alert icmp any -> $HOME_NET any (msg: "test of ping";)

The result-  'nothing'!  Actually, a different rule further down the rule
chain was triggered.  I presume since mine was not detected it continued to
evaluate the rules in the icmp_info.rules file until it found an alert that

I also tried  - no joy.

Anyone have any suggestions?  I'm kinda in a tough spot - this is not the
rule I need... I simply need to be able to write rules and identify that
single ips are to be applied.

Any assistance will greatly be appreciated.

Direct responses are also greatly appreciated...
Citadel85 at ...661...

