Snort mailing list archives

RE: Excluding IPs in HOME_NET?


From: "AJ Butcher, Information Systems and Computing" <Alex.Butcher () bristol ac uk>
Date: Fri, 04 Jun 2004 08:51:36 +0100



--On 03 June 2004 11:01 -0500 SRH-Lists <giermo () 333tech com> wrote:

I don't want to run multiple instances of Snort or any other
workarounds
like that, I just want Snort to globally ignore traffic coming from a
few specific IP addresses.  Has anyone successfully managed
to get this
working?

Paul Martin

Tack a bpf on to the end of your commandline, or create a file with the
bpf string in it and refer to it with the -F cmdline option or with the

I'd second this approach as being preferable to a pass rule; doing this at the pcap stage will reduce unnecessary load on snort.

-steve

Best Regards,
Alex.
--
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing             GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9




-------------------------------------------------------
This SF.Net email is sponsored by the new InstallShield X.
From Windows to Linux, servers to mobile, InstallShield X is the one
installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: