Project

General

Profile

Actions

Bug #267

closed

Problem with [ipvars] in icmp rule

Added by Edward Fjellskål over 13 years ago. Updated over 13 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:

Description

Trying out:
alert icmp $HOME_NET any -> [8.8.4.4,8.8.8.8] any (msg:"IDS is alive - ping google-dns test signature"; classtype:misc-activity; sid:30100000; reference:url,gamelinux.org; rev:1;)

The above rule does not fire...

Changing it to:
alert icmp $HOME_NET any -> any any (msg:"IDS is alive - ping test signature"; classtype:misc-activity; sid:30100001; reference:url,gamelinux.org; rev:1;)

This rule fires....

Actions

Also available in: Atom PDF