[Snort-users] How can i stop alerts that come from my own ip range?

Matt Olney molney at ...1935...
Wed May 5 11:52:54 EDT 2010


You may also wish to consider

var EXTERNAL_NET !$HOME_NET


On Wed, May 5, 2010 at 11:40 AM, Joel Esler <jesler at ...1935...> wrote:
> Yeah, I wouldn't do a pass rule at all.  Sounds like to me, exactly what
> Matt said.  Define your HOME_NET as the network you want to protect.
>  EXTERNAL_NET, leave as any.  Go from there.
>
> On Wed, May 5, 2010 at 11:36 AM, Stephen Mullins
> <steve.mullins.work at ...11827...> wrote:
>>
>> You could just create 3 pass rules (tcp, udp, icmp) based on your
>> $HOME_NET variable.
>>
>> Wouldn't recommend it, though, since traffic from your home net may be
>> indicative of trojan call backs and so forth.
>>
>> You want to pass all traffic with a source IP within your $HOME_NET
>> variable with a destination that you didn't state.  I suppose you want
>> to pass all home_net to home_net traffic?  Passing all home_net to
>> !home_net traffic would be a "pretty bad idea."
>>
>> Steve Mullins
>>
>> On Wed, May 5, 2010 at 10:42 AM, Pat McNamara <pmcnamara at ...14830...> wrote:
>> > Hi all,
>> > what I am trying to do is any alerts that come from my ip range is to
>> > have
>> > snort disregard them and not even write them to the MySql database. I
>> > think
>> > it must be some how set in the external_Net but I can't seem to figure
>> > it
>> > out.
>> > Thanks
>> > Pat
>> >
>> > Pat McNamara
>> > IT Systems Administrator
>> > .NU domain, Ltd.
>> > Worldnames, Inc.
>> > +1-508-359-5600 x116
>> > pmcnamara at ...14830...
>> >
>> >
>> >
>> >
>> >
>> > ------------------------------------------------------------------------------
>> >
>> > _______________________________________________
>> > Snort-users mailing list
>> > Snort-users at lists.sourceforge.net
>> > Go to this URL to change user options or unsubscribe:
>> > https://lists.sourceforge.net/lists/listinfo/snort-users
>> > Snort-users list archive:
>> > http://www.geocrawler.com/redir-sf.php3?list=snort-users
>> >
>>
>>
>> ------------------------------------------------------------------------------
>> _______________________________________________
>> Snort-users mailing list
>> Snort-users at lists.sourceforge.net
>> Go to this URL to change user options or unsubscribe:
>> https://lists.sourceforge.net/lists/listinfo/snort-users
>> Snort-users list archive:
>> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>
>
> ------------------------------------------------------------------------------
>
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>




More information about the Snort-users mailing list