Can not use suricata address-book names in address-group definitions #13135
-
Version2.4.70 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU48 RAM512G Storage for /445.07 GiB Storage for /nsm11.64 TiB Network Traffic Collectiontap Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailIn my experience it is common to define suricata's EXTERNAL_NET as "!$HOME_NET" in deployment scenarios where the sensor isn't tasked with detection of lateral movement. This was possible in 2.4.60 but the CIDR regex check in place on 2.4.70 prevents the use of address-book names in address-group definitions with error Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
We've created an issue to fix this: |
Beta Was this translation helpful? Give feedback.
We've created an issue to fix this:
#13136