[Snort-users] HTTP-Proxy scan attempts

McCammon, Keith Keith.McCammon at ...3497...
Mon Jul 1 13:42:37 EDT 2002


Comes up fine for me.  Here it is, at any rate:

Q: How do I ignore traffic coming from a particular host or hosts?

A: Write pass rules and add the host(s) to the portscan-ignorehosts list.
   Call Snort with the -o option to activate the pass rules.
   See http://www.snort.org/docs/writing_rules/ for more information.

A: Use bpf on the commandline to ignore a host (for example):

       $ snort <commandline options> not host 192.168.0.1





More information about the Snort-users mailing list