[Snort-users] bpf filter versus "config ignore_ports"

Martin Olsson elof at ...6680...
Tue Dec 6 02:31:02 EST 2005

Which is better for performance, filter out unwanted traffic using a
bpf filter or using the configuration statement "ignore_ports"?

I'm guessing that bpf is better. So when should one use "ignore_ports"?


More information about the Snort-users mailing list