I know how to specify networks and hosts in my BPF filter file, though am not sure how to prevent snort from ever seeing GRE, OSPF, IGMP, IPSec traffic, etc... Does anyone know how? Regards, Aaron