]> git.ipfire.org Git - ipfire-2.x.git/commitdiff
suricata: EXTERNAL_NET should equal any
authorMichael Tremer <michael.tremer@ipfire.org>
Tue, 23 Apr 2019 19:45:42 +0000 (20:45 +0100)
committerMichael Tremer <michael.tremer@ipfire.org>
Tue, 23 Apr 2019 19:45:42 +0000 (20:45 +0100)
This enables that we scan servers in ORANGE for clients in
GREEN which absolutely makes sense.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/suricata/suricata.yaml

index cb4f338658516289a266bc402375f417c18cf637..e921781cf7889e83c7000c5c8fa6fd82a0334a34 100644 (file)
@@ -11,8 +11,7 @@ vars:
     # Include HOME_NET declaration from external file.
     include: /var/ipfire/suricata/suricata-homenet.yaml
 
-    EXTERNAL_NET: "!$HOME_NET"
-    #EXTERNAL_NET: "any"
+    EXTERNAL_NET: "any"
 
     HTTP_SERVERS: "$HOME_NET"
     SMTP_SERVERS: "$HOME_NET"