[Snort-users] portscan question

程军杰 cjj0 at ...785...
Mon Nov 13 20:41:20 EST 2000


My snort version is 1.6.3+p2,my rules file looks like:

preprocessor portscan-ignorehosts: $DNSSERVERS
preprocessor portscan: $HOME_NET 3 5 /var/log/snort/portscan.log

I defined the ignorehosts $DNSSERVERS,but portscan module still 
display my dns server in portscan.log.

Can anybody tell me why?

Thanks.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20001114/33ee346f/attachment.html>


More information about the Snort-users mailing list