[Snort-users] False positives from DNS servers

Siddhartha Jain s_i_d_j at ...131...
Thu Mar 15 04:21:12 EST 2001


 Hi,
 
 I have the following entry in snort.conf :-
 
 var DNS_SERVERS
 [202.54.1.30/32,202.54.1.18/32,202.87.39.13/32,202.87.39.14/32]
 
 I still get portscan alerts from these hosts in ~logdir/log and
 ~logdir/portscan.log
 
 Why is this so?
 
 Siddhartha
 
 


_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com





More information about the Snort-users mailing list