[Snort-users] Rules Question

Roy Kidder rkidder at ...13076...
Fri Feb 25 05:31:39 EST 2005

I'm trying to write what I expected to be a simple set rules, but it's not
working for me. They look like this:

pass udp any any <> 53
pass udp any any <> 53
alert udp any any <> any 53 (msg: "DNS Query";)

What I expected was to alert on any DNS queries except those to or
to Instead, I'm seeing alerts on everything including those two

Any pointers on what I did wrong?

Thanks in advance,

Roy Kidder
Network Engineer
Safelite Glass Corp.

More information about the Snort-users mailing list