Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 4.23 How can I Up: 4 Rules and Alerts Previous: 4.21 Are rule keywords

4.22 Can Snort trigger a rule by MAC addresses?

Not exactly. Snort logs MAC addresses and other L2 info within the packets. The arpwatch pre-processor can watch for games with MAC address changes. But there is no facility for triggering Rules form the L2 information. The content search keywords and depth and offset begin from the L3 payload, though we haven't tried playing with really big offsets yet :-).