[Snort-users] FAQ...

Christoph Ganser chganser at ...811...
Fri Nov 17 14:14:56 EST 2000


hi 

thanks a lot for the hints. 
is there a possebility to ignore the
portscan-detection, only if the packets
are going to or comming from port 53 on specific hosts.  

kind of
 portscan-ignore_port_on_host: host.domain.tld:53 

bye

christoph

--
Christoph Ganser
Zuerich, Switzerland
PGP http://www.uplink.ethz.ch/~chganser/pgp_keys.asc
Mobile: +41 76 580 72 90

> "preprocessor portscan-ignorehosts: dns1.domain.tld 111.222.111.222
> dns3.domain.tld"
> This should ignore those hosts.  




More information about the Snort-users mailing list