The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to use snort rules to detect IP communication between specific hosts

Prev Next

This section explains how to construct Snort rules that can detect TCP, UDP, or ICMP communication between specific hosts or networks based on IP address.

Note

To detect TCP, UDP and ICMP communication between a set of IP addresses, you must create 3 separate rules.

TCP communication

To detect TCP communication between hosts specify ip_proto:tcp; and flags:S as the attack parameters.

Example:

alert tcp 10.1.1.10 any -> [192.168.230.0/24, 192.168.231.0/24] any (msg:”Malicious TCP Traffic”;ip_proto:tcp;flags:S;sid:3121;)

Here 10.1.1.10 is an example source IP and [192.168.230.0/24, 192.168.231.0/24] are the example destination subnets.

If you do not specify flag:S the rule is triggered for all the TCP packets between the specified hosts.

UDP communication

To detect UDP communication between hosts, specify ip_proto:udp; as the attack parameter.

Example:

alert udp 10.1.1.10 any -> [192.168.230.0/24, 192.168.231.0/24] any (msg:”Malicious UDP Traffic”;ip_proto:udp;sid:3122;)

Here 10.1.1.10 is an example source IP and [192.168.230.0/24, 192.168.231.0/24] are the example destination subnets. The Sensor sends alerts for any UDP packet detected between the specified hosts.

ICMP communication

To detect ICMP communication between hosts, specify ip_proto:icmp; as the attack parameter.

Example:

alert ip 10.1.1.10 any -> [192.168.230.0/24, 192.168.231.0/24] any (msg:”Malicious ICMP Traffic”;ip_proto:icmp;sid:3123;)

Here 10.1.1.10 is an example source IP and [192.168.230.0/24, 192.168.231.0/24] are the example destination subnets.

In the rule, use the following parameters along with icmp for a more specific detection:

itype - Use this to check for a specific ICMP type value

Syntax: itype:[<|>]<number>[<><number>];

icode - Use this to check for a specific ICMP code value.

Syntax: icode: [<|>]<number>[<><number>];

Example:

alert icmp 10.1.1.10 any -> [192.168.230.0/24, 192.168.231.0/24] any (msg:"example for itype and icode"; itype 8; icode:0; sid:2022; priority:3;)

Here 10.1.1.10 is an example source IP and [192.168.230.0/24, 192.168.231.0/24] are the example destination subnets. This rule is triggered for inbound traffic where the type is 8 and code is 0.