[Snort-users] RE: Bad Loop Back Traffic

Scott Elgram SElgram at ...10477...
Wed Feb 25 06:34:08 EST 2004

    There are no F5 products in my network at all.  I took a closer look at
the alerts in acid and source is the interface that the sensor is on and
destination is any number of IP's that SNORT is monitoring.
-Scott Elgram

----- Original Message ----- 
From: "Finney Charles E" <FinneyCharlesE at ...2134...>
To: <snort-users at lists.sourceforge.net>
Sent: Tuesday, February 24, 2004 10:39 AM
Subject: [Snort-users] RE: Bad Loop Back Traffic

>Reply-To: "Scott Elgram" <SElgram at ...10477...>
>From: "Scott Elgram" <SElgram at ...10477...>
>To: <snort-users at lists.sourceforge.net>
>Date: Mon, 23 Feb 2004 13:56:25 -0800
>Organization: VerifPoint/CreDENTALs
>Subject: [Snort-users] Bad Loop Back Traffic
>    I have an abundance of alerts telling me
>url[snort] BAD-TRAFFIC loopback traffic on
>According to snort this is due to improperly configured interfaces.  =
>Which part is improperly configured and how can I fix this? Or have I =
>been hacked?
>-Scott Elgram
>IT/Systems Support
>(949)770-5290 ext. 26

We have seen this traffic in copious quantities from F5 Networks BigIP
systems.  Perchance?


SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-users mailing list