next up previous contents
Next: Dynamic Modules Up: Attribute Table Example Previous: Attribute Table Affect on   Contents

Attribute Table Affect on rules

Similar to the application layer preprocessors, rules configured for specific ports that have a service metadata will be processed based on the service identified by the attribute table.

When both service metadata is present in the rule and in the connection, Snort uses the service rather than the port. If there are rules that use the service and other rules that do not but the port matches, Snort will ONLY inspect the rules that have the service that matches the connection.

The following few scenarios identify whether a rule will be inspected or not.


next up previous contents
Next: Dynamic Modules Up: Attribute Table Example Previous: Attribute Table Affect on   Contents
Eugene Misnik 2013-05-08