# Address-group arrays with AND instead of OR?

**URL:** <https://forum.suricata.io/t/address-group-arrays-with-and-instead-of-or/4594>\
**Category:** Help\
**Tags:** suricata\
**Created:** [April 11, 2024, 12:30pm UTC](https://forum.suricata.io/t/address-group-arrays-with-and-instead-of-or/4594 "2024-04-11T12:30:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pirx](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/pirx/32/2794_2.png) [@pirx](https://forum.suricata.io/u/pirx)\
**Post date:** [April 11, 2024, 12:30pm UTC](https://forum.suricata.io/t/address-group-arrays-with-and-instead-of-or/4594/1 "2024-04-11T12:30:58Z")

</div>

Just installed Suricata (6.0.10) from apt in Debian 12. Might upgrade to a newer Suricata soon, but for now i run with what apt provides.

For instance, the HOME\_NET variable in suricata.yaml can be an array, like this

```auto
HOME_NET: "[192.168.0.0/16,10.0.0.0/8,172.16.0.0/12]"

```

Thats implicitly OR between those nets.

What if i wanted an AND? Possibly even with a negated value, is that possible?

For instance something like this

```auto
EXTERNAL_NET: "!$HOME_NET"
YAHOO: "1.2.3.0/24"
EXT_NOT_YAHOO: "[$EXTERNAL_NET _and_ !$YAHOO]"

```

Does that make sense? If possible, how do i write that?  
[12.1. Suricata.yaml — Suricata 8.0.0-dev documentation](https://docs.suricata.io/en/latest/configuration/suricata-yaml.html#rule-vars) does not mention such cases.

Then, i would use this to alter some rules

```auto
From:
alert http $HOME_NET any -> $EXTERNAL_NET any ...
To:
alert http $HOME_NET any -> $EXT_NOT_YAHOO any ...

```

Yahoo is just an example:)

---

<div class="post-metadata">

**Author:** ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)\
**Post date:** [April 25, 2024, 6:39pm UTC](https://forum.suricata.io/t/address-group-arrays-with-and-instead-of-or/4594/2 "2024-04-25T18:39:55Z")

</div>

It’s just a list, so if there is a check for `HOME_NET` as long as one of the IPs is one of those listed the signature would match (given the case that all the rest of the signature matches as well).

As you can see with `EXTERNAL_NET` negation is working. So you could try `EXT\_NOT\_YAHOO:“[$EXTERNAL\_NET,!$YAHOO]”.

---

<div class="post-metadata">

**Author:** ![pirx](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/pirx/32/2794_2.png) [@pirx](https://forum.suricata.io/u/pirx)\
**Post date:** [April 26, 2024, 8:03am UTC](https://forum.suricata.io/t/address-group-arrays-with-and-instead-of-or/4594/3 "2024-04-26T08:03:43Z")

</div>

Yes, but it sounds like that would match “ext\_net” OR “not yahoo”.

What i am looking for is “ext\_net” AND(but) “not yahoo” 🙂

---

<div class="post-metadata">

**Author:** ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)\
**Post date:** [July 31, 2024, 8:02pm UTC](https://forum.suricata.io/t/address-group-arrays-with-and-instead-of-or/4594/4 "2024-07-31T20:02:23Z")

</div>

Did you actually try the example?
