| Search Site |
| Search Rules |
| Account |
| not registered? |
| can't login? |
| user preferences |
|
|||||||||||||||||||||||
|
Next: Snort Inline Rule Application Up: Snort Overview Previous: Changing Alert Order Contents
|
|||||||||||||||||||||||
| Note: You can also replace sections of the packet payload when using Snort Inline. See Section 1.5.3 for more information. |
When using a reject rule, there are two options you can use to send TCP resets:
config layer2resetstells Snort Inline to use layer2 resets and uses the MAC address of the bridge as the source MAC in the packet, and:
config layer2resets: 00:06:76:DD:5F:E3will tell Snort Inline to use layer2 resets and uses the source MAC of 00:06:76:DD:5F:E3 in the reset packet.
| Terms of Use | Privacy Policy | forum archives | site feedback ©2009 Snort and Sourcefire are registered trademarks of Sourcefire, Inc. All rights reserved. |