[Snort-users] Snort Rules

Martin Roesch roesch at ...421...
Tue Mar 6 08:24:20 EST 2001


Read http://www.snort.org/snort_rules.html

   -Marty

John Johnson wrote:
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
>  I need to make a rull set and I am having trouble understanding what
>  order and how to manage this. I am still new to snort
> so hang with me please.  I need to detact any inbound icmp to
> 192.168.250.27 and any inbound on tcp port 1521 I am not
> sure how to format the rull..
> 
> - -John
> 
> -----BEGIN PGP SIGNATURE-----
> Version: PGP 7.0.1
> 
> iQA/AwUBOp17RgfP+qzR55XlEQJDZwCeIc0l+pHAqKeaBfej1Zyt3VxPkNMAnino
> WKGrkk7PNHdaav2bOC3waJ9u
> =Yo+C
> -----END PGP SIGNATURE-----
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> http://lists.sourceforge.net/lists/listinfo/snort-users

--
Martin Roesch
roesch at ...421...
http://www.snort.org




More information about the Snort-users mailing list