Snort mailing list archives

3 quick questions


From: storm <storm-shadow () comcast net>
Date: Mon, 03 Jun 2002 16:31:03 -0400

3 quick questions. 

1. Below is an example of the beginning of my snort.conf. I *attempted* to correctly define the HOME_NET. I noticed one 
line was set to "HOME_NET any", so I put a # sign in front of it. Was I correct in doing this?? I figured defining 
HOME_NET once was enough.

2. When I go to edit the SNORT DECODER. Do I simply just uncomment the existing lines? 

3. snort -A fast -c /full/route/to/snort.conf      is the proper way to run in IDS mode with alerting correct? 

TIA 
storm

PS: the first time i tried to send this, it didnt go through

Current thread: