[Snort-users] rule creation

Leonardo Pezente lmpezente at ...11827...
Wed Mar 13 14:19:19 EDT 2013


hey all

i want to know if there is a way to create a rule to alert most of the ips
but open an exception for some of then, like:

the ips of 10.10.10.0 - 10.10.10.10 can acess the port 22 without genete an
alert, but any other one alert if they try to acess.

How can i do that?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20130313/84628606/attachment.html>


More information about the Snort-users mailing list