|
|
|
|
Snort Forums Archive
Archive Home » Rules » Ignoring certain IP address'
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Ignoring certain IP address'
Posted by amd599 on March 25, 2005 12:58:58
Today I found out that a lot of my network traffic that SNORT is picking ip is coming from our printers. I have the IP address' of about 15 printers that are connected, how can I set SNORT to ignore those IP address'? You mentioned something about 'surpress' but I'm not sure exactly how that works. I'm looking through the SNORT Manual but can't seem to find anything on it. Please let me know, thanks again. |
|
Posted by novowels on March 26, 2005 12:11:44
You have three options.
1) suppress the events you do not want to see.
2) create pass rules for those systems to cause snort to ignore them.
3) use a BPF to cause snort to not see the traffic.
I suspect a little better tuning and you would not need any of these. Have you set HOME_NET? |
|
|
|
|
|