Hi, I have set up snort and my portscan.log file is full of spp_portscans from my internal addresses to outside addresses on port 80. I put this down to normal http traffic, is it normal and why does it happen? Thank you. http://movies.yahoo.com.au - Yahoo! Movies - Vote for your nominees in our online Oscars pool.