Snort: Rules with flow:established won't trigger alerts?



  • Hi all,

    I've been struggling with getting Snort rules to trigger alerts. After 3 days of testing I finally manage to trigger alerts, but only after removing flow:established from all the rules… I've search Google for it and found that many people seems to have the very same problem. But sad enough, no solution was to be found.
    Has anyone here had the same problem?
    pfSense 2.0.1-RELEASE (amd64), Snort 2.9.1 pkg v. 2.1.1

    Have a nice day all!

    Cheers,
    Jack-Benny


Log in to reply