[Snort-users] GRE preprocessor and rules

Ana Serrano Mamolar B00315494 at ...17757...
Thu Feb 16 14:09:03 EST 2017


Hi,

Does somebody know how to use rules to filter by the inner IP in case of GRE encapsultation?

That is, in the following case,



| Eth | IP1 | GRE | IP2 | TCP | Payload |


is it possible by default trigger an alert matching a rule with IP2 ?

Thanks





-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20170216/a5bb96cf/attachment.html>


More information about the Snort-users mailing list