[Snort-users] ip's outside of HOME_NET showing up
straightflush at ...11827...
Thu Jul 8 08:02:24 EDT 2004
I finally got my acid/mysql setup working well. However i have
HOME_NET defined as my public range , say 22.214.171.124/24. However i
am seeing tons of destination ip addresses outside of that. Shouldnt
snort only be watching attacks destined for the HOME_NET network ? Or
do i need to specifically limit that with a BPF filter? I thought
snort handled that with the HOME_NET variable but still am seeing all
sorts of ip addresses in ACID.
More information about the Snort-users