[Snort-users] Port scan and MISC Large ICMP Packet

CGI synecoro at ...4554...
Mon Mar 4 06:30:03 EST 2002

1.I have o lot of Spp_portscan signature (snort and
acid)and I would like to remove it. My sensor is
working in a environment with load balacieng servers
so port scanning is normal. Where is this signature
because I didn't found it?

2. I have a connection between a web-server and MSsql
server on port 6000. the problem is the sensor is
reacting on each transaction and the signature is MISC
Large ICMP Packet. How can I separate the normal
traffic and tell the sensor not to react?


Find, Connect, Date! http://personals.yahoo.ca

More information about the Snort-users mailing list