HOME and EXT net variables
imagine the following configuration in yaml:
I think we should just ERR exit on that (with the latest git).
Instead Suricata loads and does not load all the rules (does not load all that use HOME_NET and EXT_NET variables in the rule, without a proper msg)
#3 Updated by Anoop Saldanha about 6 years ago
Victor Julien wrote:
Maybe it's a good idea to have a global check at start up as well. Give a fatal error if EXTERNAL_NET is !HOME_NET and HOME_NET is any.
If we are checking it shouldn't be just for HOME_NET or EXTERNAL_NET. WE will have to check every address specified in conf to see if they have a !any set amongst them.
Can do this. Np
#9 Updated by Anoop Saldanha about 6 years ago
- File 0001-bug-454-global-check-to-see-if-address-and-port-vars.patch 0001-bug-454-global-check-to-see-if-address-and-port-vars.patch added
- File 0002-bug-454-add-unittests-for-the-address-port-conf-var-.patch 0002-bug-454-add-unittests-for-the-address-port-conf-var-.patch added
- File 0003-bug-454-rebase-fix.-Also-use-better-error-code-to-in.patch 0003-bug-454-rebase-fix.-Also-use-better-error-code-to-in.patch added
rebased and reattached the patches from the start.