Snort custom.rules
-
hi
i would add rules in custom.rules but if i add any rule save it without error but if i would restart interface it's don't start
:-[
that exemple of my custom rule : alert tcp any 80 -> any any (msg:"HTTP trafic ";sid:9000010;)
i don't know why ?? -
Did you check the Snort errors in the system logs?
Btw, you have to set the classtype option in your custom rules.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.