[Snort-users] Problems configuring react: msg;

Peter Fraser pjfraser82 at ...11827...
Tue Nov 25 22:43:36 EST 2014


I have setup snort running as an IPS using NFQUEUE.

I can detect rules and run block and deny on them however I cannot seem to
get react to respond with a html page.

here is my configure command:

./configure --enable-sourcefire --enable-open-appid --enable-react

I am running Snort

my rule example is:

drop tcp any any -> any $HTTP_PORTS  (msg:"http://www.news.com.au";
content:"news.com.au"; react: msg; sid:283; rev:1;)

I have followed the docs and I am happy to accept all defaults at this
stage with regard to the response but the connection still just times out

Any help is greatly appreciated.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20141126/a54271a1/attachment.html>

More information about the Snort-users mailing list