Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 3.13 Why does the Up: 3 Configuring Snort Previous: 3.11 Why are there

3.12 How do you get Snort to ignore some traffic?

Snort can be made to ignore traffic in a number of different ways:

  1. Specify bpf filters on the command line the tcpdump man page has a description of bpf filters.
  2. Use a pass rule
  3. The portscan preprocessor has it's own special exclusion list with the portscan-ignorehosts.rules file directive