[Snort-users] FTP rules, different port

Michael B miboe60 at ...125...
Sun Apr 26 09:00:29 EDT 2015

I have enabled the 'protocol-ftp' rules in PulledPork, however several FTP attacks are not reported. I went to check for the rules, and they almost all have port '21' hardcoded as a port, instead of the more general '$FTP_PORTS' variable..
My FTP server is running on another port, and is thus not protected by most of the 21 rules.. Do I have to copy paste them in my custom ruleset, or is there something that I'm missing?

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20150426/4ff54e90/attachment.html>

More information about the Snort-users mailing list