[Snort-users] Updating Snort Rules...Made Easy..sort of

James Hoagland hoagland at ...47...
Tue Oct 16 11:11:11 EDT 2001


At 5:33 AM -0700 10/10/01, auto241065 at ...1284... wrote:
>On Tue, 9 Oct 2001 21:55:36 GMT, Dr SuSE <drsuse at ...748...> wrote:
>>For the rules you do not want, simply add them to the pass.rules file and
>>change them from alert to pass. 
>
>Some of us don't do this because we don't want to ignore this 
>traffic if it hits another existing rule or one we write in the 
>future. By the way, if you pass TCP traffic, that doesn't cause 
>SPADE to ignore it as well, correct?
>

Correct, but you can tell Spade what your homenet is using 
spade-homenet (this is something almost all Spade users would want). 
The format is a space-separated list of IP addresses and CIDR 
formatted addresses.

Regards,

  Jim




More information about the Snort-users mailing list