[Snort-users] -o and pass/alert/log usage
hoagland at ...47...
Thu Jun 28 11:48:04 EDT 2001
At 4:05 PM -0700 6/27/01, Joe Fico wrote:
>Well I changed my rules to look like this.
>#pass icmp 172.16.100.9/32 any <- any any (msg:"PASSING ICMP from N.A. NOC
>alert icmp 172.16.100.9/32 any <- any any (msg:" ALERTING ICMP FROM N.A. NOC
>and I got this message.
>Jun 27 15:54:52 localhost snort: ALERTING ICMP FROM N.A. NOC Server:
>172.16.100.9 -> 18.104.22.168
>so thats cool now I can uncomment out the pass rule and I get...
>Why don't I get a message for the pass rule?
Because pass rules do not generate alerts or messages. They just
stop the search for any other rule.
|* Jim Hoagland, Associate Researcher, Silicon Defense *|
|* hoagland at ...47... *|
|* http://www.silicondefense.com/ *|
|* Silicon Defense - Technical Support for Snort *|
|* Voice: (530) 756-7317 Fax: (530) 756-7297 *|
More information about the Snort-users