Snort mailing list archives
ICMP logs
From: jan () hundert6 de
Date: Fri, 25 May 2001 14:49:59 -0000 (GMT)
Oh well... I've tried to write a pass rule for ICMP type 3 code 3 from my border router to my firewall. It looks like this: pass icmp my.border.router/32 any -> my.fire.wall/32 any (itype:"3";icode:"3";) Snort doesn't complain and starts nicely, but keeps logging them, although I DID specify -o. Version's 1.7, Platform FreeBSD 4.2 STABLE. Any suggestions? Drives me mad. Cheers, Jan -- Radio HUNDERT,6 Medien GmbH Berlin - EDV - j.muenther () radio hundert6 de _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- ICMP logs jan (May 25)
- RE: ICMP logs jan (May 25)
- <Possible follow-ups>
- Re: ICMP logs Neil Dickey (May 25)
- Re: ICMP logs jan (May 25)