Snort - Suppression List



  • I have Snort running on Pfsense 2.2RC. I would like guidance on which alerts I can safely add to the suppression list. It is unclear what the meaning of "Unknown" vs. :not suspicious". I am trying to configure the Snort system for the longer term. The Pfsense platform is an Xeon E-3 with 16 GB and a 10K rpm hard drive.



  • @ghkrauss:

    I have Snort running on Pfsense 2.2RC. I would like guidance on which alerts I can safely add to the suppression list. It is unclear what the meaning of "Unknown" vs. :not suspicious". I am trying to configure the Snort system for the longer term. The Pfsense platform is an Xeon E-3 with 16 GB and a 10K rpm hard drive.

    There is a thread here with "Master Suppress List" in the title.  Do a search and it should pop up.  It is several pages worth of posts from experienced users here.

    Edit:  found the link for you:  https://forum.pfsense.org/index.php?topic=56267.0

    Bill


Log in to reply