[Snort-users] Applying a rule on entire session

Dennis George easyeinfo at ...131...
Wed Sep 8 01:54:02 EDT 2004

>>flowbits and looking for the FIN and/or RST flags?

I mean to say that the rules should be applied to the reassembled data chunk of the entire session. The rule should not be applied to each packet coming.... instead after all the packet form a session then only apply that rule.........

"Alex Butcher, ISC/ISYS" <Alex.Butcher at ...11254...> wrote:

--On 07 September 2004 20:48 -0700 Dennis George 

> Hi all,
> Is it possible to apply a particular rule only after catching the entire
> session, not on every packet............ ??

flowbits and looking for the FIN and/or RST flags?

> Thanks in advance........
> Dennis

Best Regards,
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9

Do you Yahoo!?
Yahoo! Mail - 50x more storage than other providers!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20040908/8e5e1bd8/attachment.html>

More information about the Snort-users mailing list