Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moosa
Contributor
Jump to solution

Variables in Snort Rules to identify Networks

Hi Everyone,

It seems like a very basic question, but I cannot find an answer for it.

In Snort Rules there are two variables commonly used: $EXTERNAL_NET and $HOME_NET

In Cisco FMC there is something called variable sets, where we define these variables and include the subnets in the variables.

Where do we do that in Check Point? I am not aware of any variables I can create in Check Point. Will it be identified by a Network Object if I create them by exact name as variables in Snort Rule? 

Thanks in advance.

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Those variables are automatically converted to “any” and cannot be set.
I presume this also applies in later versions than R80.30 as well.
See: https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ThreatPrevention_AdminGuide/...

View solution in original post

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Those variables are automatically converted to “any” and cannot be set.
I presume this also applies in later versions than R80.30 as well.
See: https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ThreatPrevention_AdminGuide/...

0 Kudos
Moosa
Contributor

Thank you. I went through that document yet missed that point, it is mentioned there. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events