Snort Suppression rules not supporting track by_dest

  • I have a suppress rule similar to the following line in my suppression rules b/c our VoIP phones trigger an alert for UDP port Sweep.
      suppress gen_id 122, sig_id 23, track by_dest, ip

    However when I go to start snort on that interface I get the following error message.
      snort[32212]: FATAL ERROR: /usr/local/etc/snort/suppress/WANSuppression(3) suppress has unknown track: by_dest.

    Based on the snort docs that I can find track by_dest is a legal syntax.  Anyone have any ideas as to what I'm doing wrong here?

  • A typo there… "by_dst" not "by_dest"

  • Thanks…I figured it was something simple.

Log in to reply