[Snort-users] HOWTO Ignore specific IP addresses
michael at ...9163...
Tue May 13 09:48:05 EDT 2003
OK slowly going brain dead here.
Current set-up is two web servers attached to a SNAZ NFS server.
When I kick Snort into action it works fine BUT I get literally hundreds of
false positives :
BAD TRAFFIC bad frag bits
MISC Large UDP Packet
A simple solution is to tell Snort to ignore this server
completely....Simply put how do I get Snort to ignore this machine
All help appreciated.
The only UK based complete e-commerce package.
Michael Parkinson BSc.(Hons)
Phone : 01279 602800
DDI : 01279 602805
Fax : 01279 600815
Mobile : 07770 380511
ICQ No. : 47666166
E-mail : michael at ...9163...
michael at ...9164...
URL : http://www.intellnet.net.uk/
More information about the Snort-users