[Snort-users] sfPortscan IP list ?

T Samp. tsamp77 at ...549...
Wed Aug 31 15:18:37 EDT 2005


I am experimenting with the sfPortscan module...

When I utilize the ignore_scanners option, I get a Snort error on
initialization: "No argument to 'ignore_scanners' config option"

I have tried  the following:

ignore_scanners {xxx.xxx.xxx.xxx/32}
ignore_scanners {$HOME_NET}
ignore_scanners {[xxx.xxx.xxx.xxx/32]}
ignore_scanners {[$HOME_NET]}

I guess I can't figure out the syntax for the IP portion of this option.

Any nudge in the right direction is greatly appreciated !





More information about the Snort-users mailing list