[Snort-users] How can write rule with a range IP?

bahamin takhtaei b_takhtaei at ...131...
Sun Jan 27 03:15:45 EST 2008


Hi,
Please tell me How can write a rule in snort with a range IP, e.g.
alert  icmp   [10.0.0.21 : 151.43.23.76 , 12.5.6.7] any -> any (sid:2000000;)

I checked this rule and found that snort only checks the first boundary of  range (10.0.0.21) in  packets!

Thanks


       
---------------------------------
Be a better friend, newshound, and know-it-all with Yahoo! Mobile.  Try it now.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20080127/f093fa30/attachment.html>


More information about the Snort-users mailing list