Some questions from a beginner
-
Hello.
I have some questions about the Snort Package.
I bought a business license on the website www.snort.org.
I am currently using Snort on WAN interface in legacy mode with “IPS Policy Security” setting.
My question is, how do the policies differ between the Free, Personal and Business license? Are there more policies available to the user with the Business license and if so, how do I recognize this in “IPS Policy Security”?
-
@M2x78
rules are available 30 days faster than registered users
idk but I suppose that your Snort Oinkmaster Code permits you to download a different file from the one available to the free users -
@M2x78 said in Some questions from a beginner:
My question is, how do the policies differ between the Free, Personal and Business license? Are there more policies available to the user with the Business license
The available IPS policy metadata is the same among all the rules subscriptions. The only difference between a paid personal subscription and a paid business subscription is the price. The Snort VRT wants more money from commercial use of their rules. The actual file downloaded is identical for both subscription packages.
The "free" registered user rules are at a minimum 30 days older than the paid rules. Stated another way, when a new exploit emerges and the Snort VRT creates a new rule to address that exploit, the new rule will immediately appear in the paid subscription package. But that new rule will not show up in the free package until a minimum of 30 days AFTER it first appeared in the paid package.
-
@bmeeks
but I can see different file names available for registered and subscriber, I may be wrong but from what I can see these is the filesregistered: snortrules-snapshot-29161.tar.gz
subscription: snortrules-snapshot-29181.tar.gz