Snort mailing list archives

Re: what is the command line to use ignore.rules - pass ip


From: hernani coelho <hernani_coelho () msn com>
Date: Fri, 22 Jan 2016 13:44:53 +0000

if i put in command line this --->
/usr/local/bin/snort -q -u snort -g snort -O 
/etc/snort/rules/ignore.rules -c /etc/snort/snort.conf -i wlan0

snort no works

On 22-01-2016 13:30, hernani coelho wrote:
hello,

i have this command line --->/usr/local/bin/snort -q -u snort -g snort
-O -c /etc/snort/snort.conf -i wlan0

to work with rule pass ip on file /etc/snort/rules/ignore.rules
i have put in file this -->
pass ip 64.4.8.0 any -> any any (msg:"Ignore this host";sid:1000001;rev:1;)
pass ip 64.4.8.1 any -> any any (msg:"Ignore this host";sid:1000001;rev:1;)
pass ip 0.0.0.0 any -> any any (msg:"Ignore this host";sid:1000001;rev:1;)

is this correct??
snort show ip's in same way.

can someone help me??
i tried BPF file but no work, the ip 0.0.0.0 is show anyway

------------------------------------------------------------------------------
Site24x7 APM Insight: Get Deep Visibility into Application Performance
APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
Monitor end-to-end web transactions and take corrective actions now
Troubleshoot faster and improve end-user experience. Signup Now!
http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!




------------------------------------------------------------------------------
Site24x7 APM Insight: Get Deep Visibility into Application Performance
APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
Monitor end-to-end web transactions and take corrective actions now
Troubleshoot faster and improve end-user experience. Signup Now!
http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: