Snort mailing list archives

RE: IP Question


From: "McCammon, Keith" <Keith.McCammon () eadvancemed com>
Date: Thu, 25 Jul 2002 17:31:13 -0400

You can place a pass rule anywhere that you want--local.rules, pass.rules, snort.conf, etc.  If you auto-update rules 
files, you'll want to put it in a file that won't be overwritten (i.e., pass.rules).

Also, if you want to flat out ignore *everything* to and from that host, you can add a filter (not host x.x.x.x) at the 
command-line.

-----Original Message-----
From: Jim Gifford [mailto:maillist () jg555 com]
Sent: Thursday, July 25, 2002 5:18 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] IP Question


Just wanted to make sure if I want to disable alerts from a certain IP
address, I need to place it the local.rules file


-------------------------------------------------------
This sf.net email is sponsored by: Jabber - The world's 
fastest growing 
real-time communications platform! Don't just IM. Build it in! 
http://www.jabber.com/osdn/xim
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



-------------------------------------------------------
This sf.net email is sponsored by: Jabber - The world's fastest growing
real-time communications platform! Don't just IM. Build it in!
http://www.jabber.com/osdn/xim
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: