Snort mailing list archives

what is the command line to use ignore.rules - pass ip


From: hernani coelho <hernani_coelho () msn com>
Date: Fri, 22 Jan 2016 13:30:58 +0000

hello,

i have this command line --->/usr/local/bin/snort -q -u snort -g snort 
-O -c /etc/snort/snort.conf -i wlan0

to work with rule pass ip on file /etc/snort/rules/ignore.rules
i have put in file this -->
pass ip 64.4.8.0 any -> any any (msg:"Ignore this host";sid:1000001;rev:1;)
pass ip 64.4.8.1 any -> any any (msg:"Ignore this host";sid:1000001;rev:1;)
pass ip 0.0.0.0 any -> any any (msg:"Ignore this host";sid:1000001;rev:1;)

is this correct??
snort show ip's in same way.

can someone help me??
i tried BPF file but no work, the ip 0.0.0.0 is show anyway

------------------------------------------------------------------------------
Site24x7 APM Insight: Get Deep Visibility into Application Performance
APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
Monitor end-to-end web transactions and take corrective actions now
Troubleshoot faster and improve end-user experience. Signup Now!
http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: