Skip to content
Discussion options

You must be logged in to vote

In airgap mode, NIDS rules are normally updated when you run soup and it copies them from the new ISO image to /nsm/repo/rules/:
https://github.com/Security-Onion-Solutions/securityonion/blob/master/salt/common/tools/sbin/soup#L719

Based on that (but without actual testing), I would think that you could manually sneakernet your new ruleset to /nsm/repo/rules/.

Replies: 4 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Answer selected by dougburks
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
4 participants