Snort home_net list seems to have no effect



  • Hi all,
    I have a snort sensor on a specific vlan that is part of my internal network (of course). Even if the default list contain my network different network, snort still fire some alerts on those internal network (so traffic coming and going to this interface in the internal network). is it supposed to work like this or is it a bug?
    Thanks!
    R.


Log in to reply