Snort mailing list archives

Re: spp


From: Joe McAlerney <joey () SiliconDefense com>
Date: Mon, 02 Jul 2001 16:05:51 -0700

Hello,

Try adding /32 netmasks to those addresses:

var DNS_SERVERS [xxx.xx.0.3/32,xxx.xxx.0.2/32]

And make sure the $DNS_SERVERS variable is on the portscan-ignorehosts
line:

preprocessor portscan-ignorehosts: $DNS_SERVERS

Lastly, are "stealth" packets being detected?  If so, see this FAQ.

http://www.snort.org/FAQ.html#q13

HTH,

-Joe M.

-- 
|   Joe McAlerney     joey () silicondefense com   |
| Silicon Defense - Technical Support for Snort |
|       http://www.silicondefense.com/          |
+--                                           --+

niko () digitalenigma com wrote:

  I am still getting bombarded with spp_portscan messages even though the
IP that I am getting the portscan from is in my $DNS_SERVERs var

Here is a modified snippet:

var DNS_SERVERS [xxx.xx.0.3,xxx.xx.0.2]

  The .0.2 is the one I am still receiving.  Any ideas??

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: