shared_mem: path
shared_mem /user/reputation/iplists
seconds.
shared_refresh <period>
period = "1 - 4294967295"
shared_refresh 60
./configure --enable-gre --enable-sourcefire --enable-flexresp3
--enable-dynamicplugin --enable-pthread --enable-linux-smp-stats
--enable-targetbased --enable-shared-rep --enable-control-socket
/user/reputation/iplists
In order to separate whitelist with blacklist, you need to specify whitelist with .wlf extension and blacklist with .blf extension.
shared_mem /user/reputation/iplists
If you want to change the period of checking new IP lists, add refresh period.
For example:
shared_refresh 300
config cs_dir:<path>
VERSION=1
<snort root>/src/tools/control/snort_control <path> 1361
<filename>, <list id>,<action>[, <zone>]+
<list id> ::= 32 bit integer
<action> ::= "monitor"|"block"|"white"
<zone> ::= [0-1051]
#ipreputation manifest file
white.wlf, 111 ,white,
black1.blf, 1112, black, 3, 12
black2.blf, 1113, black, 3, 12
monitor.blf,2222, monitor, 0, 2, 8