To ignore the packet with pass, you will need to start snort with -o
I use this on freeBSD, you cant use snort on freeBSD for the pass part, you can log it, but if you want to reject it aswell as log, you will have to install snort_inline which can be found on http://snort-inline.sourceforge.net compile it with ipfw
tar -zxvf snort_inline-2.3.0-RC1.tar.gz
./configure --enable-inline --enable-ipfw
Then just add it to one of the rule files.
This will work for Soldier of fortune II servers. Not tested with any other games, but i'm sure I can install an test them some time.
Hope this helps, anyone else got any ideas?
Server Management - AdminGeekZ.com Infrastructure Management, Web Application Performance, mySQL DBA. System Automation.
WordPress/Magento Performance, Apache to Nginx Conversion, Varnish Implimentation, DDoS Protection, Custom Nginx Modules
Check our wordpress varnish plugin. Contact us for quote: [email protected]