[Snort-users] Eliminating rulesets

Jeff Elkins jeff at ...4830...
Sat Feb 9 16:27:02 EST 2002


Thanks.

I'll research invert before I repost. Wouldn't want to make someone drink an 
extra beer :)

Jeff


On Saturday 09 February 2002 06:08 pm, you wrote:
> On Sat, Feb 09, 2002 at 01:42:42PM -0500, Jeff Elkins wrote:
> > I'm not trying to promote alcohol usage, but I have a newbie question:
> >
> > I'm evaluating Snort on a Linux DSL/firewall box that also serves as a
> > mail server and webserver (Sendmail/Apache).  The boxen inside the
> > firewall are all Linux as well. I've commented out the Microsoft-specific
> > rulesets (IIS,Frontpage and Cold Fusion). Other than statistics
> > gathering, is there any reason I'd want them applied?
>
> You might want to invert them.
>
> > I was getting a _bunch_ of IIS alerts before I turned them off, btw.
> >
> > Thanks,
> >
> > Jeff Elkins
> >
> >
> >
> >
> >
> > _______________________________________________
> > Snort-users mailing list
> > Snort-users at lists.sourceforge.net
> > Go to this URL to change user options or unsubscribe:
> > https://lists.sourceforge.net/lists/listinfo/snort-users
> > Snort-users list archive:
> > http://www.geocrawler.com/redir-sf.php3?list=snort-users




More information about the Snort-users mailing list