Exclude HOME_NET from EXTERNAL_NET #13176
-
Version2.4.70 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationairgap Hardware SpecsExceeds minimum requirements CPU16 RAM128G Storage for /1T Storage for /nsm350M Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailGood day, I would like to know what needs to be written in WebInterface Administration - Configuration - Suricata - config - vars - address-group - EXTERNAL_NET to exclude the HOME_NET. I did tried, !$HOME_NET but it seems the only input has to be numerical values (IP addresses). I did some online research, read the documentation but everything I found was !$HOME_NET but it does not work. Any assistance would be much appreciated Thanks Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
This is a known bug. You can apply the changes manually of wait until 2.4.80 for the fix: https://github.com/Security-Onion-Solutions/securityonion/pull/13156/files |
Beta Was this translation helpful? Give feedback.
This is a known bug.
You can apply the changes manually of wait until 2.4.80 for the fix: https://github.com/Security-Onion-Solutions/securityonion/pull/13156/files