On Sat, Sep 23, 2000 at 02:24:12PM -0700, Dragos Ruiu wrote:
> Depending on how your masquerade/nat box is configured
> it should stop the portscans from ever reaching your interior
> net and thus no alarms on the interior.  Have you tried to 
> look at the data in the "sniffer" mode to verify the packets 
> are there?
Well, on the Snort box, yes.  I did
snort -v | grep <whatever the IP was>
It didn't come up with anything.
