EFW Support

Support => General Support => Topic started by: seh2000 on Wednesday 01 February 2012, 07:03:04 am



Title: How to find specific snort rule? > Solved
Post by: seh2000 on Wednesday 01 February 2012, 07:03:04 am
Hi all,

I have been away from the forum on few for a long period due to .

Upgraded to the EFW 2.5.1 thanks to the team for a great job.

Now, I need to deactivate a few of the SNORT rules, but how do I find the actual rule in the rule files?
Lets say I want to deactivate this rule "[1:2002157:9] ET POLICY Skype User-Agent detected..." the in which of the files do I find this rule? Like it is not in the files 'auto/emerging-virus.rules' or in 'auto/emerging-policy.rules' 
I know 2002157 is the SNORT ID and I know I find the rule in one of the rule files, but which one?
Is there somewhere a list showing each rule in each file?

Your input is much appreciated.

BR// Steen

Oops!!!
Solved, in the example did not check the 'auto/emerging-policy.rules' file properly!
Sorry about!
Steen