Snort mailing list archives

Re: Updating Snort Rules...Made Easy..sort of


From: James Hoagland <hoagland () SiliconDefense com>
Date: Tue, 16 Oct 2001 11:09:01 -0700

At 5:33 AM -0700 10/10/01, auto241065 () hushmail com wrote:
On Tue, 9 Oct 2001 21:55:36 GMT, Dr SuSE <drsuse () drsuse org> wrote:
For the rules you do not want, simply add them to the pass.rules file and
change them from alert to pass.

Some of us don't do this because we don't want to ignore this traffic if it hits another existing rule or one we write in the future. By the way, if you pass TCP traffic, that doesn't cause SPADE to ignore it as well, correct?


Correct, but you can tell Spade what your homenet is using spade-homenet (this is something almost all Spade users would want). The format is a space-separated list of IP addresses and CIDR formatted addresses.

Regards,

 Jim

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: