This is a discussion on RE: [Snort-users] snort and clarckconnect gatway within the Snort forums, part of the System Security and Security Related category; Add a suppress entry in your threshold.conf That's the correct way. =20 -----Original Message----- From: snort-users-admin@...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
Add a suppress entry in your threshold.conf
That's the correct way. =20 -----Original Message----- From: snort-users-admin@lists.sourceforge.net = [mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of Thomas = Debost Sent: Thursday, February 24, 2005 9:14 AM To: snort-users@lists.sourceforge.net Subject: [Snort-users] snort and clarckconnect gatway hi, Snort pinpointed a weird (i think) behaviour. My CC gateway periodically pings my ADSL router. this small network = being obviously considered as outside, snort raises an alert for each ICMP packet. This is quite annoying as it is basically false alarm (isn't = it?). multiple solutions now: 1. add the network composed of the router and the external gateway to = the HOME_NETWORK. 2. comment out the correct signatures in /et/snort/icmp-info.rules. 3. block ICMP packets between the router and the gateway. which one would be your favourite ? Thanks Tomdeb ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://ads.osdn.com/?ad_ide95&alloc_id=14396&op=3Dick _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=3Dort-users ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |