[Snort-users] question regarding pass rule

Larry Wichman larrywichman at ...131...
Fri Nov 5 13:33:39 EST 2004


I am trying to add a pass rule so that I do not see
any events from a certain source IP. I have added the
following rule to snort.conf:

pass tcp 128.1.102.214  any -> $HOME_NET any

I have also added the following option to the snort
startup file:

# set config file & path to snort executable
SNORT_PATH=/usr/local/bin
#other options
OPTIONS="-D""-O"
CONFIG=/etc/snort/snort.conf

Am I doing something wrong?

~Larry





		
__________________________________ 
Do you Yahoo!? 
Check out the new Yahoo! Front Page. 
www.yahoo.com 
 





More information about the Snort-users mailing list