I had been using the 2.0.X branch of snort with my PureSecure since last year. And up until Friday I have been using the 2.0.6 version from them.
I had asked to get the 2.1.0 version of snort and they said there was was too many bugs in it and that it actually reported alerts wrong. Turn out they were right and snort has been fixed with the 2.1.1 version.
I also received the 2.1.1 version from Demarc, even though Im not a customer. Maybe it is because I had asked for the 2.1.0 version.
I had to copy over pcre.dll too. But they also told me that http_decode was not supported in 2.1.X anymore and that I had to make some conf changes to use http_inspect.
Too bad you had to go through all this work. I would try writing them next time.




Reply With Quote