|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [Snort-users] Preprocessor port scan ignore host
From: Joel Esler (joel.esler
sourcefire.com)
Date: Tue Dec 20 2005 - 09:55:22 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
You could enter the netrange of your internal servers ex. 192.168.1.0/24 in
the ignore_scanners line in sfportscan. Check out the Manual for all kinds
of tuning options on sfportscan.
Joel
On 12/20/05 10:52 AM, "Joshua Brown" <joshua.l.b
gmail.com> wrote:
> Can any one tell me how to ignore a large group of host from being seen as
> port scanning? This would be mostly to ignore internal servers.
>
> ~Joshua
>
-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems? Stop! Download the new AJAX search engine that makes
searching your log files as easy as surfing the web. DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click
_______________________________________________
Snort-users mailing list
Snort-users
lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]