Snort mailing list archives

Guardian with Snort - Help


From: Imran Ahmad <ira () bby com au>
Date: Fri, 9 May 2003 15:18:11 +1000

Hi;

I am new to Snort and to this list.
I have setup Snort successfully and now trying to setup "Guardian". Couldn't
find and list for Guardian..
I am running FreeBSD based firewall with three interfaces (Internal,
External and DMZ).
My External and DMZ are on the same C class which has been subneted. Now in
my Guardian.ignore file, I have defined my external C class. 
Snort is producing Attack Alerts and Guardian is detecting it. But instead
of block the attack it's producing the following log message
Odd.. source = Attacker's IP, dest = (My Class Address) - No action done.   

Any help will be appreciated.


Regards;

Imran Ahmad                                      
IT Manager
_____________________________________________________________
Burdett Buckeridge Young Limited
A participating organisation of the Australian Stock Exchange

Level 17, 60 Margaret St
Sydney NSW 2000
Direct: +61 2 9226 0059
Fax:    +61 2 9226 0066         

Email:   ira () bby com au
Website: www.bby.com.au








Current thread: