[Snort-users] ignore host?

Randy Walinga randy at ...11621...
Sat Apr 10 14:46:05 EDT 2004


snort.conf reads your rules, so you could put it there if you want but it
makes a lot more sense to put it in your local.rules file.

Yes you need the -o command line parameter when you start snort if you want
pass rules to take precedence.

As indicated, this is all in the manual... or you could get the Snort 2.0
Intrusion Detection book by Brian Caswell.  It's pretty good.



-----Original Message-----
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net]On Behalf Of
eric-dated-1083277626.193075aa63e273 at ...11523...
Sent: April 10, 2004 3:03 PM
To: MEGA Hospedagem
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] ignore host?


On Sat, 2004-04-10 at 15:44:43 -0300, MEGA Hospedagem proclaimed...

> I should add that on snort.conf ? Does it need the -o parameter?
>
> the "pass ip xxx.xxx.xxx.xxx any <> any any" (as said by Randy
> Walinga) could be put on snort.conf too? they both do the same thing?
>

no, in your rule.

RTFM

<http://www.snort.org/docs/snort_manual/node10.html>


-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users





More information about the Snort-users mailing list