Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to disable snort_decoder rules?

How do you disable snort_decoder rules?   Like this:

They don't show up in the Signature lists.


I know how to disable Individual Signatures, but the decoder don't show up.  I've even disabled the entire Misc category and it does not disable these.



This thread was automatically locked due to age.
Parents Reply
  • Nope, no good.   Note that none of the snort signatures in that list match the rule that is firing.   But, I went and selected all of them, with allow,  just to give it a try and it did not help.  I get several thousand of these a day. 

    As in my previous post, it is also triggered by IPv6 traffic and IPv4 unicast TCP/UDP traffic.  Certainly not a rule match for a "IPv4 broadcast".

    FYI, I am in bridge mode, if that helps.

    Thanks!

Children