Re: Not being able to run the Trojan rules in the update script and performance increase SOLUTION
Posted by
Wisiwyg on
Mar 07, 2016; 1:26am
URL: https://itus.accessinnov.com/Not-being-able-to-run-the-Trojan-rules-in-the-update-script-and-performance-increase-SOLUTION-tp304p315.html
Thank you for this find...
So you're saying if you *do* want to run the _trojan rules then you *do* need to change the line and you *do* add the no_stream_inserts to the end of the "config detection" in the snort.conf file?
my original entry is:
config detection: search-method ac-split search-optimize max-pattern-len 20
If I want to run the trojan rules and optimize the speed could I do this with your recommended edits?
config detection: search-method ac-nq split-any-any search-optimize max-pattern-len 20 no_stream_inserts
TIA
Shield Pro v1, Chaos Calmer, FW 1.51 SP1, v8.3.2, Bridge Mode