Snort mailing list archives
Re: Snort rules problem
From: Y M <snort () outlook com>
Date: Fri, 8 Mar 2013 18:12:14 +0300
That's what I meant but obviously not what I wrote :) YM ________________________________ From: Joel Esler<mailto:jesler () sourcefire com> Sent: 3/8/2013 5:51 PM To: Y M<mailto:snort () outlook com> Cc: Tural Nazirov<mailto:tural-666 () mail ru>; snort-sigs () lists sourceforge net<mailto:snort-sigs () lists sourceforge net> Subject: Re: [Snort-sigs] Snort rules problem On Mar 8, 2013, at 3:25 AM, Y M <snort () outlook com> wrote:
Rules enablement/disablement follow certain policy, with default, if I am not mistaken, is connectivity.
It's actually balanced.
If you use PulledPork, it will handle this for you and enable/disable rules based on the policy you choose. Reference: blog.snort.org/2012/01/importance-of-pulledpork.html
------------------------------------------------------------------------------ Symantec Endpoint Protection 12 positioned as A LEADER in The Forrester Wave(TM): Endpoint Security, Q1 2013 and "remains a good choice" in the endpoint security space. For insight on selecting the right partner to tackle endpoint security challenges, access the full report. http://p.sf.net/sfu/symantec-dev2dev
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- Snort rules problem Tural Nazirov (Mar 07)
- <Possible follow-ups>
- Re: Snort rules problem Y M (Mar 08)
- Re: Snort rules problem Joel Esler (Mar 08)
- Re: Snort rules problem Y M (Mar 08)