Snort block

  • I noticed that there are entries in my Alert tab that are not in the Block tab.  The entries all happen to have a Priority of 1 and src = my WAN interface.  Are they not being blocked because of the priority, or because they are outgoing?

  • Does anyone have any idea about this?  This seems to be an important concept of Snort that I'd like to learn.  Once again, for all enabled rules, some only alert, while other alert and block.  What determines blocking?

Log in to reply