I understand what you are saying. The reason you are getting the alerts is because you do not have your http_inspect_server lines set. Therefore the Snort process has to say "ALL traffic in OR out is mine".
If you tell it which is YOURS then it doesn't have to analyze outbound traffic except in web-client.rules.




Reply With Quote