Force10 Networks 100-00055-01 manual Keyword, Description, Rule Syntax, ttl number = number

Models: 100-00055-01

1 132
Download 132 pages 61.04 Kb
Page 121
Image 121
ttl: [number {><=}  number-

Table 28 Description of P-Series Snort Keywords

Keyword

Description

Rule Syntax

 

 

 

ttl

This keyword checks for the specified IP time-to-live

ttl: [number {><=} number-

 

value.

{-><=}] number;

 

 

 

uricontent

Searches the normalized request URI field for the

uricontent: [!] data_string”;

 

specified content.

 

 

data_string can contain mixed text and binary data.

 

 

Binary data is enclosed within pipe characters and is

 

 

written in hexadecimal form.

 

P-Series Installation and Operation Guide, version 2.3.1.2

121

Page 121
Image 121
Force10 Networks 100-00055-01 manual Keyword, Description, Rule Syntax, ttl number = number, uricontent ! “datastring”