[Snort-users] Can't suppress "(snort decoder) Bad Traffic Same Src/Dst IP"

Mike Kelley mikek at ...12706...
Mon Oct 17 13:50:29 EDT 2005


I have read and re-read those pages on the manual ... I find nothing in
the config <DIRECTIVES> area of the snort manual that hints it would
help me suppress this traffic (system wide let alone for 2 IP's) ....
help a blind PHB (<== Dilbertism) to see


Mike 
-----Original Message-----
From: Matt Kettler [mailto:mkettler at ...4108...] 
Sent: Monday, October 17, 2005 2:32 PM
To: Mike Kelley
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] Can't suppress "(snort decoder) Bad Traffic
Same Src/Dst IP"

Mike Kelley wrote:
> I have 2 machines for which this traffic is "normal" I have looked for
> the rule that triggers SPECIFFICALLY this alert ... I can't find it 

This isn't a rule, it's an alert generated directly by the snort decoder
itself.

http://www.networksecurityarchive.org/html/Snort-Signatures/2005-09/msg0
0066.html





More information about the Snort-users mailing list