[Snort-users] how enable icmp snort-2.9.6.1

hernani coelho.hernani at ...16858...
Tue Jun 17 06:39:25 EDT 2014


> hello,
>
> i put preprocessor and error disappear  but snort dont detect icmp.
>
>
> this is preprocessor portscan
>
>
> preprocessor sfportscan: proto  { all } scan_type { all } memcap {
> 10000000 } sense_level { High }
>
>
>
> and this
>
> preprocessor stream5_global: track_tcp yes, \
>      track_udp yes, \
>      track_icmp yes, \
>      max_tcp 262144, \
>      max_udp 131072, \
>      max_active_responses 2, \
>      min_response_seconds 5
> Preprocessor stream5_icmp:
>
>    thanks
>
> hernani coelho
>
>
hello,
*when i make this command --->*  sudo /usr/local/snort/bin/snort -A 
console -u snort -g snort -c /usr/local/snort/etc/snort.conf -i wlan0

*i get this error ---> *WARNING: Stream5 ICMP misconfigured (policy 0).
ERROR: Stream5 not properly configured... exiting
Fatal Error, Quitting..




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20140617/8c566775/attachment.html>


More information about the Snort-users mailing list