[Snort-users] Reputation Preprocessor
jonasabebe at ...11827...
Mon Oct 1 10:52:40 EDT 2012
OK. Then i have a related question. Is there a way (if any) that i can pass
a black list file to snort from Mysql database at run time?
Thanks a lot
On Tue, Sep 25, 2012 at 5:28 PM, Joel Esler <jesler at ...1935...> wrote:
> On Sep 25, 2012, at 5:04 AM, Yonas Abebe <jonasabebe at ...11827...> wrote:
> Does the reputation preprocessor of Snort simply drops packets coming
> from/to IP addresses listed in black list file?
> Yes. The whitelist file tells Snort explicitly "Do not block these"
> Or do I have to create rules for those IP addresses in the the black list
> There should be two rules to uncomment in the preprocessor.rules file in
> order to make it work properly.
> Joel Esler
> Senior Research Engineer, VRT
> OpenSource Community Manager
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-users