Snort mailing list archives

Flexible Response: Heads up


From: "Bob McDowell" <bmcdowell () coxhealthplans com>
Date: Tue, 21 Jan 2003 08:49:00 -0600


I cleverly got my iptables firewall stuck in a loop last night using
flexible response.  It didn't occur to me at the time, but do not set the
'bad traffic' rule for 'tcp port zero' to reset.

The end result was one bad packet followed by iptables and snort having a
war to see who could spam my logs the most.  I've never seen a screen scroll
so fast...



Bob McDowell
IS Specialist
Cox HealthPlans, LLC
417.269.2848


Current thread: