Block a high bandwidth host from snort using BPF rule

Comments

3 comments posted
Snort 2.4.3

I should add this is for Snort 2.4.3, the new version of Snort 2.8.0.1 allows you to add BPF rules from within /etc/sysconfig/snort, you can specifiy the line as above or point it to a file with all your extra config

Posted by Tim on Wed, 01/09/2008 - 21:13
Block subnet range

Or if you want to block a subnet you can use the following:-

not net 192.168.1.0/24

Useful if you have snort listening on the same interface as your LAN traffic (i.e. standalone server)

Posted by Tim on Tue, 01/22/2008 - 11:54
I tried not net

I tried not net 192.168.1.0/24 but it hasn't blocked anything. Any other suggestions?
___________
Mathew Farney | Web Hosting

Posted by Anonymous on Tue, 02/23/2010 - 14:57

Post new comment

  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is used to make sure you are a human visitor and to prevent spam submissions.
Image CAPTCHA
Enter the characters shown in the image.