OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Snort-users] Preprocessor port scan ignore host

From: Joel Esler (joel.eslersourcefire.com)
Date: Tue Dec 20 2005 - 09:55:22 CST


You could enter the netrange of your internal servers ex. 192.168.1.0/24 in
the ignore_scanners line in sfportscan. Check out the Manual for all kinds
of tuning options on sfportscan.

Joel

On 12/20/05 10:52 AM, "Joshua Brown" <joshua.l.bgmail.com> wrote:

> Can any one tell me how to ignore a large group of host from being seen as
> port scanning? This would be mostly to ignore internal servers.
>
> ~Joshua
>

-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems? Stop! Download the new AJAX search engine that makes
searching your log files as easy as surfing the web. DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click
_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users