Snort mailing list archives
RE: icmp
From: Oliver Friedrichs <of () securityfocus com>
Date: Wed, 14 Nov 2001 14:21:48 -0800
This isn't really the right thing to do. Especially not if the host really exists, the real host will respond, and so will your IDS. Unless either (a) the host doesn't exist or (b) the ICMP is also blocked by a firewall. Also, is there any reason you want to be generating additional network traffic on purpose? - Oliver -----Original Message----- From: Peter.VE () pandora be [mailto:Peter.VE () pandora be] Sent: Wednesday, November 14, 2001 2:44 AM To: snort-users () lists sourceforge net Subject: [Snort-users] icmp Hi, I'm running snort 1.8.2 on Win2K I want to block ICMP (by replying to a echo request with echo_host_unreachable) Can I do this ? Does anyone have any documents on using & configuring snort on Win2K ? I'm still trying to find out how it works, but I haven't found it yet... thanks _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- icmp snortlst snortlst (Oct 22)
- RE: icmp John Berkers (Oct 24)
- Re: icmp snortlst snortlst (Oct 24)
- Re: icmp snortlst snortlst (Oct 24)
- icmp again snortlst snortlst (Oct 25)
- RE: icmp John Berkers (Oct 24)