[Snort-users] GRE preprocessor and rules

Ana Serrano Mamolar B00315494 at ...17757...
Thu Feb 16 14:09:03 EST 2017


Does somebody know how to use rules to filter by the inner IP in case of GRE encapsultation?

That is, in the following case,

| Eth | IP1 | GRE | IP2 | TCP | Payload |

is it possible by default trigger an alert matching a rule with IP2 ?


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20170216/a5bb96cf/attachment.html>

More information about the Snort-users mailing list