Snort mailing list archives

RE: icmp


From: Oliver Friedrichs <of () securityfocus com>
Date: Wed, 14 Nov 2001 14:21:48 -0800

This isn't really the right thing to do.  Especially not if the host really
exists, the real host will respond, and so will your IDS.  Unless either (a)
the host doesn't exist or (b) the ICMP is also blocked by a firewall.  Also,
is there any reason you want to be generating additional network traffic on
purpose?

- Oliver

-----Original Message-----
From: Peter.VE () pandora be [mailto:Peter.VE () pandora be] 
Sent: Wednesday, November 14, 2001 2:44 AM
To: snort-users () lists sourceforge net
Subject: [Snort-users] icmp


Hi,

I'm running snort 1.8.2 on Win2K
I want to block ICMP (by replying to a echo request   with
echo_host_unreachable)

Can I do this ?

Does anyone have any documents on using & configuring snort on Win2K ? I'm
still trying to find out how it works, but I haven't found it yet...

thanks



 
_______________________________________________ Snort-users mailing list
Snort-users () lists sourceforge net Go to this URL to change user options or
unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: