No subject


Thu Nov 23 16:36:19 EST 2017


will only do one variable substitution per line.  I'm
not sure, though; that's not my code.

The thresholds are not used for ignorehosts.  But remember
that any TCP stealth packets will always trip a scan
detection from an ignorehost.

Try doing the listing in one line and tell me if that
works.  Also, you don't have to have the "/32" netmask
for a single host.  It'll work fine, but you can have
just the IP address.


~Patrick 




More information about the Snort-users mailing list