Snort mailing list archives

Portscan does not ignore my net


From: "Smith, Aron" <AronSmith () users com>
Date: Mon, 17 Mar 2003 23:15:59 -0500

I have an ignore rule for 10.28/16 and the -o option specified.  Initially it worked, but after clearing out the 
database of old alerts, snort is ignoring my ignore rule again and I have thousands of portscan events that are 
actually legit traffic.

Anyone else seen this problem?

Current thread: