Destination Address and Port
The destination address and port follow the direction operator. The syntax of these parameters are the same as the source address and port. See “Source Addresses” on page 64, and “Ports” on page 65.
Snort Rule Options
Options are made of a keyword and an argument. An argument is the packet data against which the rule is matched. Option keywords are followed by a colon, and each option is puncutated with a
P-Series Rule Syntax
capture/forward_policy on channel Snort_rule
•capture/forward policy can have four values: alert, permit, divert, or deny. These settings are described in Table 5 on page 28.
•channel can be c0 for Channel 0, c1 for Channel 1, or all for both channels.
•Snort_rule is a rule written in Snort syntax.
Table 18 shows an example
Table 18
alert on c1 any any
Note:
P-Series Supported Snort Keywords
Table 19 lists Snort keywords that the
Table 19 Supported Snort Keywords for Static and Dynamic Rules
| Keyword | Static | Dynamic |
|
|
|
|
|
|
| ack | Yes | Yes |
|
|
|
|
|
|
| content | Yes, no negative. | No |
|
|
|
|
|
|
|
|
|
|
|
66 | Writing Rules |