Snort Configuration



  • I have a subscription to Emerging Threats ETPro. I notice that just using ETPro with Snort will not allow configuration of the wan interface. Does one have to use snort rules with ETPro rules? How does one configure Snort for use of Emerging Threat ETPro ruleset?

    Thanks for any assistance.



  • @ghkrauss:

    I notice that just using ETPro with Snort will not allow configuration of the wan interface.

    That is not true.  You can use any rule set on any configured interface.  What leads you to think Snort does not support ETPro on the WAN interface?

    @ghkrauss:

    Does one have to use snort rules with ETPro rules?

    No, you can use just the Emerging Threats rules if you like (or just the Snort GPLv2 Community rules, or any combination of ET, VRT and Community rules).

    @ghkrauss:

    How does one configure Snort for use of Emerging Threat ETPro ruleset?

    On the GLOBAL SETTINGS tab click the checkbox to enable ETPro rules then type your subscription code into the text box that will appear.  The page uses dynamic HTML to show/hide form fields as different options are enabled.  Be sure you are using a current version browser that supports dynamic HTML (pretty much anything these days will).

    There is a sticky thread in the Packages forum for quickly setting up Snort for new users.  You may find it helpful.

    Bill


Log in to reply