Snort mailing list archives

MAC Address Q...


From: "World Internet Now! - Lists" <lists () win1 net>
Date: Tue, 15 May 2001 16:54:56 -0500

I am new to snort, if fact, just installed it last week.  I am running it
under win32 and haven't had any problems so far.  However, I have received
thousands of "attacks" over the last 5 days.  Most of them I am sure are
false alarms, however, this is not my problem.  Over 80% of these are
traffic between mac addresses.  No IP address is logged.  Most are things
like IDS171/ping zeros or IDS162/ping-nmap-icmp and seem to be traffic
between my router and a select few other hosts.  Is this something that I
should be concerned with, and more importantly, if not, is there a way I can
make snort ignore the traffic or at least report the IP and not the mac?
TIA.


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: