Snort mailing list archives

RE: HTTP-Proxy scan attempts


From: "McCammon, Keith" <Keith.McCammon () eadvancemed com>
Date: Mon, 1 Jul 2002 16:41:15 -0400

Comes up fine for me.  Here it is, at any rate:

Q: How do I ignore traffic coming from a particular host or hosts?

A: Write pass rules and add the host(s) to the portscan-ignorehosts list.
   Call Snort with the -o option to activate the pass rules.
   See http://www.snort.org/docs/writing_rules/ for more information.

A: Use bpf on the commandline to ignore a host (for example):

       $ snort <commandline options> not host 192.168.0.1



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: