Snort - Suppression List
-
I have Snort running on Pfsense 2.2RC. I would like guidance on which alerts I can safely add to the suppression list. It is unclear what the meaning of "Unknown" vs. :not suspicious". I am trying to configure the Snort system for the longer term. The Pfsense platform is an Xeon E-3 with 16 GB and a 10K rpm hard drive.
-
I have Snort running on Pfsense 2.2RC. I would like guidance on which alerts I can safely add to the suppression list. It is unclear what the meaning of "Unknown" vs. :not suspicious". I am trying to configure the Snort system for the longer term. The Pfsense platform is an Xeon E-3 with 16 GB and a 10K rpm hard drive.
There is a thread here with "Master Suppress List" in the title. Do a search and it should pop up. It is several pages worth of posts from experienced users here.
Edit: found the link for you: https://forum.pfsense.org/index.php?topic=56267.0
Bill