Snort mailing list archives
Re: Ignoring a packet
From: "Paul Melson" <pmelson () gmail com>
Date: Wed, 20 Jun 2007 17:14:13 -0400
How do I tell snort to ignore a specific packet? I am collecting snmp
data from my DMZ and I see it in
snort but I want snort to ignore the packets because I am being inadated
with them. 1) If you never want to hear about this event no matter the specific source or destination, disable the rule (comment it out with a #). 2) If you want to ignore all SNMP traffic from certain hosts or subnets, you can use the -F switch and create a bpf filter. 3) If the packets you want to ignore have a specific payload, then you need to write a pass rule. More info on all of these is available in the online documentation: http://snort.org/docs/snort_htmanuals/htmanual_2615/ PaulM ------------------------------------------------------------------------- This SF.net email is sponsored by DB2 Express Download DB2 Express C - the FREE version of DB2 express and take control of your XML. No limits. Just data. Click to get it now. http://sourceforge.net/powerbar/db2/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Ignoring a packet Louis Bohm (Jun 20)
- Re: Ignoring a packet Joel Esler (Jun 20)
- Re: Ignoring a packet Paul Melson (Jun 20)