Snort mailing list archives
Re: Updating Snort Rules...Made Easy..sort of
From: James Hoagland <hoagland () SiliconDefense com>
Date: Tue, 16 Oct 2001 11:09:01 -0700
At 5:33 AM -0700 10/10/01, auto241065 () hushmail com wrote:
On Tue, 9 Oct 2001 21:55:36 GMT, Dr SuSE <drsuse () drsuse org> wrote:For the rules you do not want, simply add them to the pass.rules file andchange them from alert to pass.Some of us don't do this because we don't want to ignore this traffic if it hits another existing rule or one we write in the future. By the way, if you pass TCP traffic, that doesn't cause SPADE to ignore it as well, correct?
Correct, but you can tell Spade what your homenet is using spade-homenet (this is something almost all Spade users would want). The format is a space-separated list of IP addresses and CIDR formatted addresses.
Regards, Jim _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Updating Snort Rules...Made Easy..sort of Dr SuSE (Oct 09)
- PGP Sign snortrules? [was: Re: Updating Snort Rules...Made Easy..sort of] Jason Haar (Oct 11)
- <Possible follow-ups>
- Re: Updating Snort Rules...Made Easy..sort of auto241065 (Oct 10)
- Re: Updating Snort Rules...Made Easy..sort of James Hoagland (Oct 16)