| To: | snort-users@lists.sourceforge.net |
|---|---|
| Subject: | [Snort-users] Cannot suppress events from a security scanner |
| From: | trashboy@free.fr |
| Date: | Thu, 05 Apr 2007 16:54:56 +0200 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | snort-list@securepoint.com |
| List-archive: | <http://sourceforge.net/mailarchive/forum.php?forum=snort-users> |
| List-help: | <mailto:snort-users-request@lists.sourceforge.net?subject=help> |
| List-id: | "Snort users talk about... Snort!" <snort-users.lists.sourceforge.net> |
| List-post: | <mailto:snort-users@lists.sourceforge.net> |
| List-subscribe: | <https://lists.sourceforge.net/lists/listinfo/snort-users>, <mailto:snort-users-request@lists.sourceforge.net?subject=subscribe> |
| List-unsubscribe: | <https://lists.sourceforge.net/lists/listinfo/snort-users>, <mailto:snort-users-request@lists.sourceforge.net?subject=unsubscribe> |
| Sender: | snort-users-bounces@lists.sourceforge.net |
| User-agent: | Internet Messaging Program (IMP) 3.2.5 |
Hi all, I would like to exclude from snort processing rules a security scanner. To do so, I've completed as follow the threshold.conf file: suppress gen_id 1, sig_id 1-9999, track by_src, ip 192.168.1.250 suppress gen_id 1, sig_id 1-9999, track by_dst, ip 192.168.1.250 Unfortunately, it doesn't works. Snort goes on processing traffic from this IP address. I've done another test specifying just one sig_id and in this case it works. Anyone can help me solve this issue ? Thanks, ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys-and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-users] Snort v2.6.1.4 Now Available, Snort Releases |
|---|---|
| Next by Date: | Re: [Snort-users] Cannot suppress events from a security scanner, Joel Esler |
| Previous by Thread: | [Snort-users] Snort v2.6.1.4 Now Available, Snort Releases |
| Next by Thread: | Re: [Snort-users] Cannot suppress events from a security scanner, Joel Esler |
| Indexes: | [Date] [Thread] [Top] [All Lists] |