[Snort-users] block question

Matt Kettler mkettler at ...4108...
Mon Sep 16 13:56:02 EDT 2002


Read the FAQ.. you need a flexresp enabled build of snort to use those 
keywords.

Also a word of warning. Do not rely on flexresp as if it were a firewall, 
it is quite possible for a skilled attacker to bypass flexresp's ability to 
reset a TCP connection. It's better used as a last ditch in case your 
firewall and other security mechanisms fail.

At 04:13 PM 9/16/2002 -0400, Ryan Hairyes wrote:
>Hello all,
>
>Can you still block packets in snort?  I used snort before (and now I've
>come back to it) and you could use react: block; to block certain things.
>Is this still true?  I noticed it is in the manual still.  However, when I
>try it in my rules it says it doesn't know what react is.
>
>Thanks for the help
>
>Ryan.
>
>
>
>
>-------------------------------------------------------
>This sf.net email is sponsored by:ThinkGeek
>Welcome to geek heaven.
>http://thinkgeek.com/sf
>_______________________________________________
>Snort-users mailing list
>Snort-users at lists.sourceforge.net
>Go to this URL to change user options or unsubscribe:
>https://lists.sourceforge.net/lists/listinfo/snort-users
>Snort-users list archive:
>http://www.geocrawler.com/redir-sf.php3?list=snort-users





More information about the Snort-users mailing list