[Snort-users] SID 376

Axness, Bob BAxness at ...7743...
Thu Dec 12 14:16:04 EST 2002


We are using Whats Up Gold to monitor network devices and servers.
One of the network devices we are monitoring is beyond our firewall and is
on the same Network as our server running Snort.
We are getting Alerts with the source address as our firewall and the
destination as the network device we are monitoring beyond our firewall.

To make a long story short we are not surprised to see this however we would
like to modify the rule with SID 376 so that when the source is x and the
destination is z -ignore it - otherwise log it.


Thanks, 
Robert Axness 


**********************************************************************
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager.

This footnote also confirms that this email message has been swept by
MIMEsweeper for the presence of computer viruses.

www.mimesweeper.com
**********************************************************************





More information about the Snort-users mailing list