Snort mailing list archives

Re: Possible Memory Overlap/Bug? Help!


From: Chris Green <cmg () sourcefire com>
Date: Thu, 12 Dec 2002 15:24:57 -0500

"Kevin P" <kevinp () routergod com> writes:

Thanks for the reply Chris.  I upgraded to build 225 (the stable release dated Dec 12).   Unfortunately, the problem 
remains.

Is there anything I can do to help track this down?

Is there any packet loss on your system?

The easiest way to help us out is to run tcpdump with 1514 snaplen and
try to correlate TCP segmented traffic with the snort alerts.

Lawrence is correct about there being an issue with packet loss and
that very well could be what you are running into.

If thats the case, I recommend you lower the number of rules loaded :)
-- 
Chris Green <cmg () sourcefire com>
Warning: time of day goes back, taking countermeasures.



-------------------------------------------------------
This sf.net email is sponsored by:
With Great Power, Comes Great Responsibility 
Learn to use your power at OSDN's High Performance Computing Channel
http://hpc.devchannel.org/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: