Project

General

Profile

Actions

Bug #8214

closed

HOME_NET includes all locally attached Networks

Added by Julian Wecke over 6 years ago. Updated over 6 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
Suricata
Target version:
-
Start date:
12/16/2017
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

When selecting a passlist to define the HOME_NET the HOME_NET always contains the locally attached networks of all interfaces(except wan). Even if the Local Networks Add firewall Locally-Attached Networks to the list (excluding WAN). option is not checked in the passlist configuration. This is different as the expected behavior.

In a scenario where your want to protect a local network from other local networks you might consider only the network from the interface suricata is running on as HOME_NET and everything else EXTERNAL.

Actions

Also available in: Atom PDF