<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Variables in Snort Rules to identify Networks in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Variables-in-Snort-Rules-to-identify-Networks/m-p/154271#M26112</link>
    <description>&lt;P&gt;Thank you. I went through that document yet missed that point, it is mentioned there.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Aug 2022 13:33:25 GMT</pubDate>
    <dc:creator>Moosa</dc:creator>
    <dc:date>2022-08-01T13:33:25Z</dc:date>
    <item>
      <title>Variables in Snort Rules to identify Networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Variables-in-Snort-Rules-to-identify-Networks/m-p/154247#M26104</link>
      <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;&lt;BR /&gt;It seems like a very basic question, but I cannot find an answer for it.&lt;BR /&gt;&lt;BR /&gt;In Snort Rules there are two variables commonly used:&amp;nbsp;$EXTERNAL_NET and $HOME_NET&lt;BR /&gt;&lt;BR /&gt;In Cisco FMC there is something called variable sets, where we define these variables and include the subnets in the variables.&lt;BR /&gt;&lt;BR /&gt;Where do we do that in Check Point? I am not aware of any variables I can create in Check Point. Will it be identified by a Network Object if I create them by exact name as variables in Snort Rule?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 21:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Variables-in-Snort-Rules-to-identify-Networks/m-p/154247#M26104</guid>
      <dc:creator>Moosa</dc:creator>
      <dc:date>2022-07-31T21:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Variables in Snort Rules to identify Networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Variables-in-Snort-Rules-to-identify-Networks/m-p/154248#M26105</link>
      <description>&lt;P&gt;Those variables are automatically converted to “any” and cannot be set.&lt;BR /&gt;I presume this also applies in later versions than R80.30 as well.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ThreatPrevention_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ThreatPrevention_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 01:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Variables-in-Snort-Rules-to-identify-Networks/m-p/154248#M26105</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-08-01T01:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Variables in Snort Rules to identify Networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Variables-in-Snort-Rules-to-identify-Networks/m-p/154271#M26112</link>
      <description>&lt;P&gt;Thank you. I went through that document yet missed that point, it is mentioned there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 13:33:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Variables-in-Snort-Rules-to-identify-Networks/m-p/154271#M26112</guid>
      <dc:creator>Moosa</dc:creator>
      <dc:date>2022-08-01T13:33:25Z</dc:date>
    </item>
  </channel>
</rss>

