[Snort-users] Ignoring all traffic from a certain network
tsevy at ...1701...
Mon Apr 15 12:42:35 EDT 2002
Don't know what others think, but I would use a BPF filter in this case.
From: Stephen C Burns [mailto:sburns at ...2404...]
Sent: Monday, April 15, 2002 12:13 PM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Ignoring all traffic from a certain network
Is there a way to have Snort and all of it's rules ignore all traffic from
a specific /24? Like a global portscan-ignorehosts directive that affects
everything, not just port scans? I get a lot of false positives in the
rules from my HOME_NET that I'd like to take out, if possible... thanks
Stephen C Burns
Farpointer Technologies, Inc.
sb at ...2404...
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
More information about the Snort-users