[Snort-users] PortScan Configuration in snort.conf

Ruiyuan Jiang Ruiyuan_Jiang at ...10944...
Wed May 19 10:26:01 EDT 2004

Thanks, Michael

It works.

Ryan Jiang

-----Original Message-----
From: Michael Steele [mailto:michaels at ...9077...]
Sent: Wednesday, May 19, 2004 10:49 AM
To: snort-users at lists.sourceforge.net
Subject: RE: [Snort-users] PortScan Configuration in snort.conf

It's still supported. Just copy your old "preprocessor portscan" line from
your old snort.conf to your new snort.conf and restart snort.

Kindest regards,

WINSNORT.com Management Team Member
Pick up your FREE Windows or UNIX Snort installation guides      
mailto:support at ...9077...
Website: http://www.winsnort.com
Snort: Open Source Network IDS - http://www.snort.org

From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Ruiyuan Jiang
Sent: Wednesday, May 19, 2004 5:22 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] PortScan Configuration in snort.conf

Hi, all 
I upgraded my snort from 2.0.5 to 2.1.2 (mysql, php, apache, ACID). After
upgrade, I don't see port scan traffic anymore in "Traffic Profile by
Protocol". I looked at the snort.conf from 2.1.2 distribution and there is
no more portscan.log item anymore. I enabled flow-portscan in snort.conf but
there is definition for the log location. I don't see portscan traffic. Am I
doing something wrong? Thanks.

Ryan Jiang 

This SF.Net email is sponsored by: SourceForge.net Broadband
Sign-up now for SourceForge Broadband and get the fastest
6.0/768 connection for only $19.95/mo for the first 3 months!
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20040519/124f35ed/attachment.html>

More information about the Snort-users mailing list