Snort mailing list archives

Re: asynchronous_link was snort sees no fragmented attack


From: Chris Green <cmg () sourcefire com>
Date: Tue, 13 Aug 2002 09:11:48 -0400

Holger.Woehle () arcor net writes:


i switched to snort 1.9 beta 2 and connected the sensor to both ends of the TAP
using device bond0.
Now i see all alerts!

But i don't want to inspect all outgoing traffic!

Well, if you really don't want to, add teh asynchronous_link option to

preprocessor stream4: <other options>, asynchronous_link

Cheers,
Chris
-- 
Chris Green <cmg () sourcefire com>
 "Not everyone holds these truths to be self-evident, so we've worked
                  up a proof of them as Appendix A." --  Paul Prescod


-------------------------------------------------------
This sf.net email is sponsored by: Dice - The leading online job board
for high-tech professionals. Search and apply for tech jobs today!
http://seeker.dice.com/seeker.epl?rel_code=31
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: