Project

General

Profile

Actions

Bug #267

closed
EF

Problem with [ipvars] in icmp rule

Bug #267: Problem with [ipvars] in icmp rule

Added by Edward Fjellskål over 15 years ago. Updated over 15 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:

Description

Trying out:
alert icmp $HOME_NET any -> [8.8.4.4,8.8.8.8] any (msg:"IDS is alive - ping google-dns test signature"; classtype:misc-activity; sid:30100000; reference:url,gamelinux.org; rev:1;)

The above rule does not fire...

Changing it to:
alert icmp $HOME_NET any -> any any (msg:"IDS is alive - ping test signature"; classtype:misc-activity; sid:30100001; reference:url,gamelinux.org; rev:1;)

This rule fires....

EF Updated by Edward Fjellskål over 15 years ago Actions #1

ohhh... crapz.... sårry with a big O...

For some reason, my interface reverted to not the one that I really use, so $HOME_NET did not match, cuz it did not see the package :/

A nice moment to test multiple interfaces though :)

E

VJ Updated by Victor Julien over 15 years ago Actions #2

  • Status changed from New to Rejected

Not an issue after all :)

Actions

Also available in: PDF Atom