[Snort-users] portscan-ignore

Fred Portnoy fportnoy at ...1527...
Tue Aug 6 08:33:03 EDT 2002


Does the portscan-ignore feature . . .
"preprocessor portscan-ignorehosts: $DNS_SERVERS"
... apply to either the source or destination addresses in the detected
scan, or only the source addresses? Can I get it to not report on what
Snort thinks are scans to port 53 of my dns servers? I am currently
running 1.8.3.



More information about the Snort-users mailing list