[Snort-users] Preprocessor port scan ignore host

Joel Esler joel.esler at ...1935...
Tue Dec 20 07:56:08 EST 2005


You could enter the netrange of your internal servers ex. 192.168.1.0/24 in
the ignore_scanners line in sfportscan.  Check out the Manual for all kinds
of tuning options on sfportscan.

Joel


On 12/20/05 10:52 AM, "Joshua Brown" <joshua.l.b at ...11827...> wrote:

> Can any one tell me how to ignore a large group of host from being seen as
> port scanning? This would be mostly to ignore internal servers.
> 
> ~Joshua
> 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20051220/9a8bb91a/attachment.html>


More information about the Snort-users mailing list