Snort mailing list archives
Re: asynchronous_link was snort sees no fragmented attack
From: Chris Green <cmg () sourcefire com>
Date: Tue, 13 Aug 2002 09:11:48 -0400
Holger.Woehle () arcor net writes:
i switched to snort 1.9 beta 2 and connected the sensor to both ends of the TAP using device bond0. Now i see all alerts! But i don't want to inspect all outgoing traffic!
Well, if you really don't want to, add teh asynchronous_link option to preprocessor stream4: <other options>, asynchronous_link Cheers, Chris -- Chris Green <cmg () sourcefire com> "Not everyone holds these truths to be self-evident, so we've worked up a proof of them as Appendix A." -- Paul Prescod ------------------------------------------------------- This sf.net email is sponsored by: Dice - The leading online job board for high-tech professionals. Search and apply for tech jobs today! http://seeker.dice.com/seeker.epl?rel_code=31 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- asynchronous_link was snort sees no fragmented attack Holger . Woehle (Aug 13)
- Re: asynchronous_link was snort sees no fragmented attack Chris Green (Aug 13)