[Snort-users] Re: Stateful portscan detection anybody?

Vitaly McLain twistah at ...93...
Thu Aug 31 00:48:17 EDT 2000


Hi,

I am in a real hurry so I could have missed something about your message,
but it seems to me you just need to add the IPs of your DNS servers to the:
preprocessor portscan-ignorehosts:
line of the rules file.

Vitaly McLain
twistah at ...93...





More information about the Snort-users mailing list