[Snort-users] spp_portscan from DNS servers

Michael Steele michaels at ...155...
Fri Oct 12 07:50:05 EDT 2001


Mike,

If you can send your Snort.conf file, I will have a look to see if I can
help.

-Mike


          Commercial Snort Support
               1.866.41.SNORT
Silicon Defense - www.silicondefense.com
Michael Steele - Snort Support Technician

-----Original Message-----
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Mike
Walter
Sent: Thursday, October 11, 2001 8:52 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] spp_portscan from DNS servers

Hello,
	I have installed and configured Snort and ACID.  I followed the
Doc on configuring my DNS servers in the snort.conf.  I have added the
DNS servers with a /32 as suggested in the SNORT FAQ.  I am still
receiving a lot of spp_portscan from my two DNS servers.  Any thoughts?
What am I missing?

Mike Walter,
3z.net a PCD Company,
PCD Network Solutions, Inc,
"When Success the Only Solution  t h i n K  3z.net"
www.pcdnet.net
www.3z.net




_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list






More information about the Snort-users mailing list