Snort mailing list archives

Re: icmp pass rules


From: Frank Knobbe <frank () knobbe us>
Date: Fri, 24 Oct 2008 11:59:42 -0500

On Fri, 2008-10-24 at 09:14 -0400, Stephen Reese wrote:
The real question is why do pass rules even exist if you could use
suppression instead and not have the performance penalty.

Because you can be way more specific with pass rules (icode, dsize,
content, etc) whereas with suppressions, you can only filter by *one* IP
address and SID.

-Frank

-- 
It is said that the Internet is a public utility. As such, it is best
compared to a sewer. A big, fat pipe with a bunch of crap sloshing
against your ports.

Attachment: signature.asc
Description: This is a digitally signed message part

-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: