[Snort-users] simple pass rules
erek at ...577...
Mon May 7 18:38:23 EDT 2001
On Mon, 7 May 2001, Aaron McKinnon wrote:
> Trying to write a simple pass rule:
> #Pass rule for uagent (ArcServe 2000 backup agent).
> pass tcp 22.214.171.124 6051 -> 126.96.36.199 any
> pass tcp 188.8.131.52 any -> 184.108.40.206 139
> It seems to ignore the rules in my local.rules file... Have I written these
> rules correctly?
Yes, those look just fine.
Are they not passing traffic? If not, be sure that you are using the '-o'
command line switch.
-o Change the rule testing order to Pass|Alert|Log
More information about the Snort-users