Snort mailing list archives
Portscan does not ignore my net
From: "Smith, Aron" <AronSmith () users com>
Date: Mon, 17 Mar 2003 23:15:59 -0500
I have an ignore rule for 10.28/16 and the -o option specified. Initially it worked, but after clearing out the database of old alerts, snort is ignoring my ignore rule again and I have thousands of portscan events that are actually legit traffic. Anyone else seen this problem?
Current thread:
- Portscan does not ignore my net Smith, Aron (Mar 17)
- Re: Portscan does not ignore my net Erek Adams (Mar 17)