Hi all,
Rule question here: I am making the following adjustment (Suricata 6.0.3):
2036303 "\\$HOME_NET any -> \\$EXTERNAL_NET 80" "[$HOME_NET,![10.2.142.32]] any -> $EXTERNAL_NET 80"
I get the following warning message:
25/5/2022 -- 09:38:21 - <Warning> -- Rule has unknown dest port var and will be disabled: EXTERNAL_NET: [1:2036303] ET HUNTING Terse Unencrypted Request for Google - Likely Connectivity Check
Thanks for the insight!