Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort.org Discussion » Snort Rules

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Snort Rules


Posted by enzoscifo on April 10, 2006 05:02:58

Hi all, I need some help about Snort rules.

How to detects an incoming connection to a specific host on the network on port 1234 with Snort?

Posted by Joel_Esler on April 10, 2006 05:27:28

This is an extremely simple rule to write, I suggest, if you are working on this for school, read the Snort Manual. It's very good and should be able to point you in the correct direction.