[Snort-users] Updating Snort Rules...Made Easy..sort of
hoagland at ...47...
Tue Oct 16 11:11:11 EDT 2001
At 5:33 AM -0700 10/10/01, auto241065 at ...1284... wrote:
>On Tue, 9 Oct 2001 21:55:36 GMT, Dr SuSE <drsuse at ...748...> wrote:
>>For the rules you do not want, simply add them to the pass.rules file and
>>change them from alert to pass.
>Some of us don't do this because we don't want to ignore this
>traffic if it hits another existing rule or one we write in the
>future. By the way, if you pass TCP traffic, that doesn't cause
>SPADE to ignore it as well, correct?
Correct, but you can tell Spade what your homenet is using
spade-homenet (this is something almost all Spade users would want).
The format is a space-separated list of IP addresses and CIDR
More information about the Snort-users