[Snort-users] rules: react

Vsevolod Zaika Vsevolod_Zaika at ...3585...
Tue Sep 25 05:15:02 EDT 2001


Is somebody use 'react' in rules?
I have installed LibNet-1.0.2a, configured and 
maked snort-1.8.1-RELEASE (build 74) 
whith --enable-flexresp.

i have included in some rules following:
 
alert tcp [bla-bla-bla] ( [bla-bla-bla]; react: block,warn; )
                                           (or simply block)

(i receive no error messages during snort starting)

but when this rule ativated nothing except logging happens.
(no session close, no warning messages to attackers etc.)

command line options to snort are:

./snort -sIDN

OS: FreeBSD 4.1.1-RELEASE.

What is wrong?

Thank you for help.


-- 
WBR, Vsevolod I. Zaika,
ISS system administrator.

[VZ666-RIPE] [VIZ1-UANIC]
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Vsevolod_Zaika.vcf
Type: text/x-vcard
Size: 359 bytes
Desc: Card for Vsevolod Zaika
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20010925/d68e2500/attachment.vcf>


More information about the Snort-users mailing list