[Snort-users] /var/log/snort/some.ip.addr.dir/ permissions pr oblem

ipwitch ipwitch at ...8462...
Thu Apr 10 16:46:04 EDT 2003


-----BEGIN PGP SIGNED MESSAGE-----

On Friday 11 April 2003 00:08, David Alonso De La Vega Tapage wrote:
> To ignore ALL ICMP traffic from host <foo> using a pass rule:
>
> 	pass icmp <foo> any -> $HOME_NET any
>
> And you _MUST_ start snort with the '-o' parameter for the pass rule to
> work correctly.
>
>
> where is the place to put this rule .. ?   inside of snort.conf file ..
>  or in other file ..  apart .. ?

rules.local
check the bottom of snort.conf, there you can see which files snorts reads 
rules from....

- -- 
public key: http://unixcluster.dk/public.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (FreeBSD)

iQCVAwUBPpYCAVHydoME146BAQGiWQQAsx9zhfJbNM3G52cQpRmmhdeto5g6/3Gp
w3new87iLAADCyqdb3iRmZHOc+YHbifloE0WHdwlnl5JB/nX6yJPpBOpuvoaszwc
waFiaypuzPz6vxYr0b9qnda1YZLHE1mfhq2QGqLbanRuMpF7TTrLCUTl+HSEejc3
6Pt6uJVXVRA=
=pH3h
-----END PGP SIGNATURE-----





More information about the Snort-users mailing list