Snort mailing list archives

Re: Error in stock 2.2rc1 snort.conf file


From: Jeremy Hewlett <jh () sourcefire com>
Date: Wed, 4 Aug 2004 15:56:31 -0400

On Tue, Aug 03, Bill Warren wrote:
I am testing using it with
/usr/local/bin/snort -c /etc/snort/etc/snort.conf -T
and I get
/etc/snort/etc/snort.conf(506) Unable to create an IPSet from [HOME_NET]

At line 506 is
include classification.config

Flow-portscan has many directives that are broken up into single lines
to make it easy to read. Each line is followed by a "\" to indicate
"this is not the end of options, move on to the next line." Thus, the
last line will not have a "\"

Here's my guess. You have some of these flow-portscan lines
uncommented. The last line you have uncommented for flow-portscan
contains a backslash... follow this down through other comments and
whatnot... the next directive is: classification.config. This is
confusing flow-portscan. 

I can reproduce your problem with the above scenario.



-------------------------------------------------------
This SF.Net email is sponsored by OSTG. Have you noticed the changes on
Linux.com, ITManagersJournal and NewsForge in the past few weeks? Now,
one more big change to announce. We are now OSTG- Open Source Technology
Group. Come see the changes on the new OSTG site. www.ostg.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: