[Snort-users] (spp_frag3) Short fragment, possible DoS attempt

Graham, Robert rgraham at ...8016...
Tue Dec 6 08:24:01 EST 2005


After upgrading to version 2.4.3 we are getting alot of (spp_frag3) Short fragment, possible DoS Attempt alerts.  These alerts are only between two internal hosts (a Redhat AS server and an old Digital Alpha).  The alerts are being triggered by NFS traffic between the two hosts.  Since this seems to be a preprocessor engine that is detecting this traffic, can snort.conf be modified to ignore these packets and how would I go about doing this?

Thanks In advance
Robert Graham
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20051206/dbf7078e/attachment.html>


More information about the Snort-users mailing list