Re: A couple of questions

"Nihal Desai \(nihdesai\) via Snort-users" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <BL0PR11MB31215B2410CA1861D4F505EAD5DF9@BL0PR11MB3121.namprd11.prod.outlook.com>
Gustaf,

You can use reject module without active module not set.
Ruleset question might be for Talos.
For “flags” rule, are you running the test in inline mode? Can you share cmd line, config and a pcap if possible? Have you tried another action like block?

Thanks!

--
V/r
Nihal N. Desai

From: Snort-users <[email protected]> on behalf of Gustaf Florén via Snort-users <[email protected]>
Date: Tuesday, May 31, 2022 at 7:04 AM
To: [email protected] <[email protected]>
Subject: [Snort-users] A couple of questions
Hi
I have a couple of questions.

1. I have active module set to active ={ attempts=2 }
What is the default nr of packets sent per response if active module is not set??
Is it safe to remove active module all together and rely on reject module only?

2.Are there rules in community ruleset that are not in registered rules?

3.I have rule below to block xmas scans, but it doesnt work, snort only notices the scan but not blocking it.How can I block xmas scans??

reject tcp any any -> $HOME_NET any ( msg:"xmas"; flags:FPU; sid:1; )

Gustaf

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.