[Snort-users] rule creation

JJ Cummings cummingsj at ...11827...
Wed Mar 13 15:11:30 EDT 2013


Yeah, but ip only rules are a bad idea kind of thing... Thus my suggestion if IPRep and BPF

Sent from the iRoad

On Mar 13, 2013, at 12:58, Jeremy Hoel <jthoel at ...11827...> wrote:

> You can do pass local.rules for some things too.  Or thresholds by src or dst.
> 
> On Wed, Mar 13, 2013 at 6:38 PM, JJC <cummingsj at ...11827...> wrote:
>> Perhaps a mixture of IP Reputation and BPF
>> 
>> On Wed, Mar 13, 2013 at 12:19 PM, Leonardo Pezente <lmpezente at ...14542....> wrote:
>>> hey all
>>> 
>>> i want to know if there is a way to create a rule to alert most of the ips
>>> but open an exception for some of then, like:
>>> 
>>> the ips of 10.10.10.0 - 10.10.10.10 can acess the port 22 without genete an
>>> alert, but any other one alert if they try to acess.
>>> 
>>> How can i do that?
>>> 
>>> ------------------------------------------------------------------------------
>>> Everyone hates slow websites. So do we.
>>> Make your web apps faster with AppDynamics
>>> Download AppDynamics Lite for free today:
>>> http://p.sf.net/sfu/appdyn_d2d_mar
>>> _______________________________________________
>>> Snort-users mailing list
>>> Snort-users at lists.sourceforge.net
>>> Go to this URL to change user options or unsubscribe:
>>> https://lists.sourceforge.net/lists/listinfo/snort-users
>>> Snort-users list archive:
>>> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users
>>> 
>>> Please visit http://blog.snort.org to stay current on all the latest Snort
>>> news!
>> 
>> ------------------------------------------------------------------------------
>> Everyone hates slow websites. So do we.
>> Make your web apps faster with AppDynamics
>> Download AppDynamics Lite for free today:
>> http://p.sf.net/sfu/appdyn_d2d_mar
>> _______________________________________________
>> Snort-users mailing list
>> Snort-users at lists.sourceforge.net
>> Go to this URL to change user options or unsubscribe:
>> https://lists.sourceforge.net/lists/listinfo/snort-users
>> Snort-users list archive:
>> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users
>> 
>> Please visit http://blog.snort.org to stay current on all the latest Snort news!




More information about the Snort-users mailing list