aboutsummaryrefslogtreecommitdiffstats
path: root/config/snort/modifysid-sample.conf
diff options
context:
space:
mode:
authorbmeeks8 <bmeeks8@bellsouth.net>2014-09-09 20:29:37 -0400
committerbmeeks8 <bmeeks8@bellsouth.net>2014-09-09 20:29:37 -0400
commit52cbc379189f48a8f456d05a46b59646c93eba01 (patch)
tree02b67602b9c02a42af9544108c950adee65afdea /config/snort/modifysid-sample.conf
parent70d22674fde78a35662fe1a210ecaca4baa984cb (diff)
downloadpfsense-packages-52cbc379189f48a8f456d05a46b59646c93eba01.tar.gz
pfsense-packages-52cbc379189f48a8f456d05a46b59646c93eba01.tar.bz2
pfsense-packages-52cbc379189f48a8f456d05a46b59646c93eba01.zip
Include new SID MGMT sample conf files in manifest.
Diffstat (limited to 'config/snort/modifysid-sample.conf')
-rw-r--r--config/snort/modifysid-sample.conf23
1 files changed, 23 insertions, 0 deletions
diff --git a/config/snort/modifysid-sample.conf b/config/snort/modifysid-sample.conf
new file mode 100644
index 00000000..d59f84ba
--- /dev/null
+++ b/config/snort/modifysid-sample.conf
@@ -0,0 +1,23 @@
+# example modifysid.conf
+#
+# formatting is simple
+# <sid or sid list> "what I'm replacing" "what I'm replacing it with"
+#
+# Note that this will only work with GID:1 rules, simply because modifying
+# GID:3 SO stub rules would not actually affect the rule.
+#
+# If you are attempting to change rulestate (enable,disable) from here
+# then you are doing it wrong. Do this from within the respective
+# rulestate modification configuration files.
+
+# the following applies to sid 10010 only and represents what would normally
+# be s/to_client/from_server/
+# 10010 "to_client" "from_server"
+
+# the following would replace HTTP_PORTS with HTTPS_PORTS for ALL GID:1
+# rules
+# "HTTP_PORTS" "HTTPS_PORTS"
+
+# multiple sids can be specified as noted below:
+# 302,429,1821 "\$EXTERNAL_NET" "\$HOME_NET"
+