Snort mailing list archives

false positive on BGP traffic


From: "Daniel Qian" <daniel.qian () supracanada com>
Date: Tue, 29 Sep 2009 21:51:21 -0400

I have a lot of alerts on BGP connections, both internal and external. The 
snort ID is 116:58 - snort_decoder: Experimental TCP options. I am wondering 
why snort alerts on this legitimate traffic. 


------------------------------------------------------------------------------
Come build with us! The BlackBerry&reg; Developer Conference in SF, CA
is the only developer event you need to attend this year. Jumpstart your
developing skills, take BlackBerry mobile applications to market and stay 
ahead of the curve. Join us from November 9&#45;12, 2009. Register now&#33;
http://p.sf.net/sfu/devconf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: