[Snort-users] icmp

Oliver Friedrichs of at ...35...
Wed Nov 14 14:20:02 EST 2001

This isn't really the right thing to do.  Especially not if the host really
exists, the real host will respond, and so will your IDS.  Unless either (a)
the host doesn't exist or (b) the ICMP is also blocked by a firewall.  Also,
is there any reason you want to be generating additional network traffic on

- Oliver

-----Original Message-----
From: Peter.VE at ...1187... [mailto:Peter.VE at ...1187...] 
Sent: Wednesday, November 14, 2001 2:44 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] icmp


I'm running snort 1.8.2 on Win2K
I want to block ICMP (by replying to a echo request   with

Can I do this ?

Does anyone have any documents on using & configuring snort on Win2K ? I'm
still trying to find out how it works, but I haven't found it yet...


_______________________________________________ Snort-users mailing list
Snort-users at lists.sourceforge.net Go to this URL to change user options or
unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:

More information about the Snort-users mailing list