<div><div dir="auto">I used HOME_NET with network <a href="http://10.20.20.0/24">10.20.20.0/24</a>. My IDS <a href="http://10.20.20.174/24">10.20.20.174/24</a> (VM in Virtualbox), kali linux <a href="http://10.20.20.82/24">10.20.20.82/24</a> (VM in Virtualbox) and My komputer 10.20.20.29. </div></div><div dir="auto"><br></div><div dir="auto">EXTERNAL_NET = any</div><div dir="auto"><br></div><div dir="auto">If i attack 10.20.20.174 with kalilinux 10.20.20.82 ===> Suricata detected</div><div dir="auto"><br></div><div dir="auto">If i attack 10.20.20.29 from kalilinux(10.20.20.82) ===> suricata not detected</div><div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, 9 Apr 2020 at 01.41 Tiago Faria <<a href="mailto:tiago.faria.backups@gmail.com">tiago.faria.backups@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div><div dir="auto">Make sure the network definitions are configured properly (what defines your internal network). </div></div><div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, 8 Apr 2020 at 08:23, yudhi ardiyanto <<a href="mailto:yudhi.ardiyanto@gmail.com" target="_blank">yudhi.ardiyanto@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Hello Guys</div><div><br></div><div>
<pre id="m_2133132251479281368m_-7897753230508943934gmail-tw-target-text" style="text-align:left" dir="ltr"><span lang="en">why suricata cannot detect attacks from other computers to other computers, but can only detect when someone attacks him</span></pre>
</div></div>
_______________________________________________</blockquote></div></div><div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br>
Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org" target="_blank">oisf-users@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" rel="noreferrer" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" rel="noreferrer" target="_blank">http://suricata-ids.org/support/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" rel="noreferrer" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
<br>
Conference: <a href="https://suricon.net" rel="noreferrer" target="_blank">https://suricon.net</a><br>
Trainings: <a href="https://suricata-ids.org/training/" rel="noreferrer" target="_blank">https://suricata-ids.org/training/</a></blockquote></div></div>
_______________________________________________<br>
Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org" target="_blank">oisf-users@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" rel="noreferrer" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" rel="noreferrer" target="_blank">http://suricata-ids.org/support/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" rel="noreferrer" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
<br>
Conference: <a href="https://suricon.net" rel="noreferrer" target="_blank">https://suricon.net</a><br>
Trainings: <a href="https://suricata-ids.org/training/" rel="noreferrer" target="_blank">https://suricata-ids.org/training/</a></blockquote></div></div>