snort-users May 2010 archive
Main Archive Page > Month Archives  > snort-users archives
snort-users: Re: [Snort-users] How can i stop alerts that come f

Re: [Snort-users] How can i stop alerts that come from my own ip range?

From: Paul Schmehl <pschmehl_lists_at_nospam>
Date: Thu May 06 2010 - 14:48:02 GMT
To: Joel Esler <jesler@sourcefire.com>, Stephen Mullins <steve.mullins.work@gmail.com>

If you make EXTERNAL_NET any, it would include your own HOME_NET. Depending
upon routing or the way a sig is written, you could then get alerts from
HOME_NET to HOME_NET.

I thought the standard convention was

var HOME_NET [your address space]
var EXTERNAL_NET !$HOME_NET

--On Wednesday, May 05, 2010 11:40:10 -0400 Joel Esler <jesler@sourcefire.com>
wrote:

> Yeah, I wouldn't do a pass rule at all.  Sounds like to me, exactly what
> Matt said.  Define your HOME_NET as the network you want to protect.
>  EXTERNAL_NET, leave as any.  Go from there.
>
>
> On Wed, May 5, 2010 at 11:36 AM, Stephen Mullins
> <steve.mullins.work@gmail.com> wrote:
>
> You could just create 3 pass rules (tcp, udp, icmp) based on your
> $HOME_NET variable.
>
> Wouldn't recommend it, though, since traffic from your home net may be
> indicative of trojan call backs and so forth.
>
> You want to pass all traffic with a source IP within your $HOME_NET
> variable with a destination that you didn't state.  I suppose you want
> to pass all home_net to home_net traffic?  Passing all home_net to
> !home_net traffic would be a "pretty bad idea."
>
> Steve Mullins
>
>
> On Wed, May 5, 2010 at 10:42 AM, Pat McNamara <pmcnamara@nic.nu> wrote:
>
>
>
>> Hi all,
>> what I am trying to do is any alerts that come from my ip range is to have
>> snort disregard them and not even write them to the MySql database. I think
>> it must be some how set in the external_Net but I can't seem to figure it
>> out.
>> Thanks
>> Pat
>>
>> Pat McNamara
>> IT Systems Administrator
>> .NU domain, Ltd.
>> Worldnames, Inc.
>> +1-508-359-5600 x116
>> pmcnamara@nic.nu
>>
>>
>>
>>
>
>
>
>> ----------------------------------------------------------------------------
>> --
>>
>> _______________________________________________
>> Snort-users mailing list
>> Snort-users@lists.sourceforge.net
>> Go to this URL to change user options or unsubscribe:
>> https://lists.sourceforge.net/lists/listinfo/snort-users
>> Snort-users list archive:
>> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>>
>
> ------------------------------------------------------------------------------
> _______________________________________________
> Snort-users mailing list
> Snort-users@lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>
>
>

-- Paul Schmehl, Senior Infosec Analyst As if it wasn't already obvious, my opinions are my own and not those of my employer. ******************************************* "It is as useless to argue with those who have renounced the use of reason as to administer medication to the dead." Thomas Jefferson ------------------------------------------------------------------------------ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users