Project

General

Profile

Actions

Feature #1140

open

IP-Address white list implementation for IPS mode (without disable a rule global)

Added by Stefan Sabolowitsch about 10 years ago. Updated almost 2 years ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Similar to the threshold.conf list, it would be good to have a white list for IPS mode.
Without such a white list for each IP address, you must disable the rule currently "global" and this is not helpful.

Please check this discussion:
https://lists.openinfosecfoundation.org/pipermail/oisf-users/2014-March/003394.html

Actions #1

Updated by Andreas Herz about 8 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
Actions #2

Updated by Victor Julien almost 2 years ago

Not sure I understand what the goal is here. But would a "pass" rule not just be enough?

Actions

Also available in: Atom PDF