From: Gabriele G. <gab...@vo...> - 2004-08-07 17:32:54
|
Hello list. I would want to know as i can make in order not to make to very work the cpu of the machine with snort_inline. I have as the cpu high percentage goes, when i take via ftp of the rows from the linux machine with snort_inline over. I have tried to to set up a syntax as "$SNORT not port 21 and not port 20 -U -X -d -D -Q -c /usr/local/etc/snort_inline.conf -w -A full -b -e -k all -i $INTERFACE -l $DIR/$DATE" in order to avoid the control of these doors but it does not work, other ways are? Even with the use in the rules of the "PASS tcp any any -> $syntax.." ? thanks in advance. G. -- |