[Snort-users] Not ignoring DNS servers

Paul Slinski pauls at ...3346...
Thu Sep 6 11:19:07 EDT 2001


ic...

My mind was ignoring the ICMP in the alert.
Thanks.

On Thu, 6 Sep 2001, Fraser Hugh wrote:

> Date: Thu, 6 Sep 2001 14:08:23 -0400
> From: Fraser Hugh <hugh_fraser at ...2804...>
> To: 'Paul Slinski' <pauls at ...3346...>
> Subject: RE: [Snort-users] Not ignoring DNS servers
>
> This alert is being generated by a rule in icmp-info.rules file, not by the
> portscan preprocessor. You need to change the "
> ICMP Destination Unreachable (Port Unreachable)" rule to exclude these
> hosts.
> > -----Original Message-----
> > From:	Paul Slinski [SMTP:pauls at ...3346...]
> > Sent:	Thursday, September 06, 2001 1:50 PM
> > To:	snort-users at lists.sourceforge.net
> > Subject:	[Snort-users] Not ignoring DNS servers
> >
> > I have snort set up the following way in snort.conf (snort rules from
> > snort site):
> >
> > var DNS_SERVERS [206.191.0.140/32,206.191.0.210/32]
> >
> > and





More information about the Snort-users mailing list