[Snort-users] HOWTO Ignore specific IP addresses

Demetri Mouratis dmourati at ...3877...
Tue May 13 10:10:02 EDT 2003


On Tue, 13 May 2003, Michael Parkinson wrote:

> Hi All,
>
> OK slowly going brain dead here.
>
> Current set-up is two web servers attached to a SNAZ NFS server.
>
> When I kick Snort into action it works fine BUT I get literally hundreds of
> false positives :
>
> BAD TRAFFIC bad frag bits
> MISC Large UDP Packet
>
> A simple solution is to tell Snort to ignore this server
> completely....Simply put how do I get Snort to ignore this machine
> completely?
>

Michael,

Please see:

http://www.snort.org/docs/faq.html#3.7


---------------------------------------------------------------------
Demetri Mouratis
dmourati at ...3878...





More information about the Snort-users mailing list