[Snort-users] scan rules on pfsense

Joel Esler jesler at ...1935...
Mon Nov 11 16:20:20 EST 2013


I think I moved most of that to indicator-scan.rules?

--
Joel Esler

> On Nov 11, 2013, at 11:46, Leonardo Pezente <lmpezente at ...11827...> wrote:
> 
> hi all,
> 
> Im using snort 2.4.9.6 on pfsense 2.1, and i have a little issue about the scan rules. im not sure if this rules still exist on this version of snort, but i didn't found any think saying that, i dont know if the problem is the pfsense. i look at the scan.rules but it was empty. i had some old scan.rules from an older version of snort and i try to put there, but didnt work. without this rules i can detect basic scans like sys portscan.
> ------------------------------------------------------------------------------
> November Webinars for C, C++, Fortran Developers
> Accelerate application performance with scalable programming models. Explore
> techniques for threading, error checking, porting, and tuning. Get the most 
> from the latest Intel processors and coprocessors. See abstracts and register
> http://pubads.g.doubleclick.net/gampad/clk?id=60136231&iu=/4140/ostg.clktrk
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users
> 
> Please visit http://blog.snort.org to stay current on all the latest Snort news!




More information about the Snort-users mailing list