[Snort-users] ip's outside of HOME_NET showing up

Adam Denenberg straightflush at ...11827...
Thu Jul 8 08:02:24 EDT 2004


Hello,

 I finally got my acid/mysql setup working well.  However i have
HOME_NET defined as my public range , say 24.100.100.0/24.  However i
am seeing tons of destination ip addresses outside of that.  Shouldnt
snort only be watching attacks destined for the HOME_NET network ?  Or
do i need to specifically limit that with a BPF filter?  I thought
snort handled that with the HOME_NET variable but still am seeing all
sorts of ip addresses in ACID.

thanks
adam




More information about the Snort-users mailing list