The Intrusion Rule Header
Every standard text rule and shared object rule has a rule header containing parameters and arguments. The following illustrates parts of a rule header:
The following table describes each part of the rule header shown above.
Rule Header Component |
Example Value |
This Value... |
---|---|---|
Action |
|
Generates an intrusion event when triggered. |
Protocol |
|
Tests TCP traffic only. |
Source IP Address |
|
Tests traffic coming from any host that is not on your internal network. |
Source Ports |
|
Tests traffic coming from any port on the originating host. |
Operator |
|
Tests external traffic (destined for the web servers on your network). |
Destination IP Address |
|
Tests traffic to be delivered to any host specified as a web server on your internal network. |
Destination Ports |
|
Tests traffic delivered to an HTTP port on your internal network. |
Note | The previous example uses default variables, as do most intrusion rules. |