27.4. Snort File Usage

As mentioned previously, a custom signature file is in Snort format and these can be created by third parties or by the system administrator. Snort is described in depth at https://snort.org. The standard form of Snort signatures is a filter followed by options:

action protocol src-net src-ports direction dest-net dest-ports ( options )

However, it is important to be aware of how some Snort file conventions are interpreted by cOS Stream and what limitations exist. This is described next.

Snort Filter Usage

The Snort filter is interpreted as follows:

Supported Options

The following Snort options are supported with any restrictions listed: