[Snort-users] icmp

Oliver Friedrichs of at ...35...
Wed Nov 14 14:20:02 EST 2001


This isn't really the right thing to do.  Especially not if the host really
exists, the real host will respond, and so will your IDS.  Unless either (a)
the host doesn't exist or (b) the ICMP is also blocked by a firewall.  Also,
is there any reason you want to be generating additional network traffic on
purpose?

- Oliver

-----Original Message-----
From: Peter.VE at ...1187... [mailto:Peter.VE at ...1187...] 
Sent: Wednesday, November 14, 2001 2:44 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] icmp


Hi,

I'm running snort 1.8.2 on Win2K
I want to block ICMP (by replying to a echo request   with
echo_host_unreachable)

Can I do this ?

Does anyone have any documents on using & configuring snort on Win2K ? I'm
still trying to find out how it works, but I haven't found it yet...

thanks



 
_______________________________________________ Snort-users mailing list
Snort-users at lists.sourceforge.net Go to this URL to change user options or
unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users




More information about the Snort-users mailing list