> My original question was how can I prevent my companies VPN 
> server showing
> up
> in snort?
> I have added the rule
> pass tcp (inet_ip) any <> (vpn_ip) any
> But I still get the following message from snort.
> " spp_stream4: TTL EVASION (reassemble) detection"

Drop packets to/from "vpn-ip" before they hit the Snort engine using BPF....

	./snort <snort options> not host (vpn-ip)

Check the Snort Users Manual or the FAQs (
http://www.snort.org/docs/faq.html#3.7 ) from more information..

- Jeff

