CONFIGURATIONS ON TEST ENVIRONMENT
snort --v
,,_ -*> Snort! <*-
o" )~ Version 2.9.12 GRE (Build 325)
'''' By Martin Roesch & The Snort Team: http://www.snort.org/contact#team
Copyright (C) 2014-2018 Cisco and/or its affiliates. All rights reserved.
Copyright (C) 1998-2013 Sourcefire, Inc., et al.
Using libpcap version 1.5.3
Using PCRE version: 8.32 2012-11-30
Using ZLIB version: 1.2.7
OS Version
cat /etc/redhat-release
CentOS Linux release 7.3.1611 (Core)
Configuration Validation
/usr/sbin/snort -T -c /etc/snort/snort.conf
Snort successfully validated the configuration!
FTP Rules are define under :
cat /etc/snort/rules/ftp.rules(attached)
TESTING
After above settings on snort when I try to make a connection on snort machine with wrong ID & PASSWORD, I did not see any message on snort console. Below snapshot is for reference.