[Snort-users] HOw to close a connection using snort.

Martin Roesch roesch at ...421...
Tue Jan 23 23:57:37 EST 2001


See http://www.snort.org/writing_snort_rules.htm for information on
writing active response rules.  They are under the "resp" keyword.

    -Marty

Sam Wun wrote:
> 
> Hi, thanks for the reply.
> Do you know how to define a rule for execute it?
> 
> Sam
> Blake Frantz wrote:
> 
> > when you ./configure, use the enable-flexresp option.  It allows you to
> > send RSTs and host/port/network unreachable packets based on whatever
> > criteria you want.
> >
> > you will need to install libnet first:
> > http://www.packetfactory.net/libnet
> >
> > hope this helps.
> >
> > blake
> >
> > On Tue, 23 Jan 2001, Sam Wun wrote:
> >
> > > >
> > >
> > > Hi,
> > >
> > > When an intrustion is detected by snort, how can I use snort to close the connection?
> > > (like ipfilter, block return-icmp ... )
> > >
> > > Thanks
> > > Sam
> > >
> > >
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> http://lists.sourceforge.net/lists/listinfo/snort-users

--
Martin Roesch
roesch at ...421...
http://www.snort.org




More information about the Snort-users mailing list