Snort mailing list archives
Guardian with Snort - Help
From: Imran Ahmad <ira () bby com au>
Date: Fri, 9 May 2003 15:18:11 +1000
Hi; I am new to Snort and to this list. I have setup Snort successfully and now trying to setup "Guardian". Couldn't find and list for Guardian.. I am running FreeBSD based firewall with three interfaces (Internal, External and DMZ). My External and DMZ are on the same C class which has been subneted. Now in my Guardian.ignore file, I have defined my external C class. Snort is producing Attack Alerts and Guardian is detecting it. But instead of block the attack it's producing the following log message Odd.. source = Attacker's IP, dest = (My Class Address) - No action done. Any help will be appreciated. Regards; Imran Ahmad IT Manager _____________________________________________________________ Burdett Buckeridge Young Limited A participating organisation of the Australian Stock Exchange Level 17, 60 Margaret St Sydney NSW 2000 Direct: +61 2 9226 0059 Fax: +61 2 9226 0066 Email: ira () bby com au Website: www.bby.com.au
Current thread:
- Guardian with Snort - Help Imran Ahmad (May 09)
- Re: Guardian with Snort - Help Snortman (Jun 04)