[Snort-users] Libnet & 'resp'

Joe McAlerney joey at ...47...
Wed Jun 20 17:14:32 EDT 2001


Hello Brent,

Make sure you configure snort with the --enable-flexresp tag, then
recompile.  Post back if you still have problems.

-Joe M.

-- 
|   Joe McAlerney     joey at ...155...   |
| Silicon Defense - Technical Support for Snort |
|       http://www.silicondefense.com/          |
+--                                           --+

Brent Kearney wrote:
> 
> Hello,
> 
> I have installed Libnet 1.0.2a on a solaris 2.7 box that is
> running snort 1.7.  After adding a rule,
> 
> alert tcp $EXTERNAL_NET any -> $HOME_NET 515 (logto:"/var/log/snort/lp.log"; resp:rst_all,icmp_port; msg:"l
> p service is protected. Connection attempt logged.";)
> 
> Snort refuses to start:
> 
> snort -A full -c /usr/local/etc/snort.conf -i le0 -l /var/log/snort -v
> 
>         --== Initializing Snort ==--
> 
> Initializing Network Interface le0
> Decoding Ethernet on interface le0
> Initializing Preprocessors!
> Initializing Plug-ins!
> Initializating Output Plugins!
> 
> +++++++++++++++++++++++++++++++++++++++++++++++++++
> Initializing rule chains...
> 
> ERROR: /usr/local/etc/snort.conf (77) => Unknown keyword "resp" in rule!
> 
> Any suggestions would be appreciated.  Please CC: brent at ...2359...,
> because I'm not on the list.
> 
> Thanks,
> 
> -Brent
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> http://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users




More information about the Snort-users mailing list