[Snort-users] Snort 2.8 and SID on pass- and alert-rules

David J. Bianco david at ...13799...
Mon Oct 22 09:00:08 EDT 2007


Vidar Hoel wrote:
> If you are right, and I have no reason to believe otherwise, what then
> the point of pass-rules?
> I mean, if it's not working they way we have used these pass-rules, what
> other ways do people use pass-rules?
> 

You're using the pass rules properly, it's only the sid values that are
wrong.  As Seth already mentioned elsewhere in the thread, you can use the
pass rules but just change the way you associate them with the original
rules.  Personally, I don't use pass rules much, but when I do I put them
just before the rule they go with, and I include comments to make clear
the relationship between the two and why the pass rule is necessary.

	David




More information about the Snort-users mailing list