Snort mailing list archives

Re: Ignoring a packet


From: "Paul Melson" <pmelson () gmail com>
Date: Wed, 20 Jun 2007 17:14:13 -0400

How do I tell snort to ignore a specific packet?  I am collecting snmp
data from my DMZ and I see it in 
snort but I want snort to ignore the packets because I am being inadated
with them.

1) If you never want to hear about this event no matter the specific source
or destination, disable the rule (comment it out with a #).

2) If you want to ignore all SNMP traffic from certain hosts or subnets, you
can use the -F switch and create a bpf filter.

3) If the packets you want to ignore have a specific payload, then you need
to write a pass rule.

More info on all of these is available in the online documentation:

http://snort.org/docs/snort_htmanuals/htmanual_2615/

PaulM


-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: