[Snort-users] Updating Snort Rules...Made Easy..sort of

auto241065 at ...1284... auto241065 at ...1284...
Wed Oct 10 05:37:06 EDT 2001


On Tue, 9 Oct 2001 21:55:36 GMT, Dr SuSE <drsuse at ...748...> wrote:
>For the rules you do not want, simply add them to the pass.rules file and 
>change them from alert to pass.  

Some of us don't do this because we don't want to ignore this traffic if it hits another existing rule or one we write in the future. By the way, if you pass TCP traffic, that doesn't cause SPADE to ignore it as well, correct?






More information about the Snort-users mailing list