Snort mailing list archives

ICMP - redirect host


From: "David Alexandre M. de Carvalho" <david () medusa ubi pt>
Date: Thu, 4 Jul 2002 09:31:58 +0100

Hi!
I have a red hat linux 7.2 configured to be a gateway to a masquerade network using ipchains.
I have lot's of snort logs, but the most frequent are:
"ICMP - redirect host. Classification: Potencially bat traffic".

If I add the rule /sbin/ipchains -N icmp-acc to accept standard ICMP errors, and a few more "config"
will this reduce the size of my logs ? Since they are mostly these messages.

Thanks.
Best regards.
David.



Current thread: