[Snort-users] Re: detecting tunnels with Snort

Michael Scheidell scheidell at ...5171...
Tue Mar 7 04:40:10 EST 2006


> -----Original Message-----
> From: snort-users-admin at lists.sourceforge.net 
> [mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Tom Le
> Sent: Monday, March 06, 2006 10:40 PM
> To: Michael Scheidell
> Cc: Radu Spineanu; snort-users at lists.sourceforge.net
> Subject: [Snort-users] Re: detecting tunnels with Snort
> 
> 
> This is assuming you could discern the packet size of the 
> encapsulated traffic...
> 

Who cares?  My example had nothing to do with packet size for
encapsulated traffic.
Read the rfc's to get a clue.




More information about the Snort-users mailing list