Snort mailing list archives

SID 376


From: "Axness, Bob" <BAxness () stjosephswb com>
Date: Thu, 12 Dec 2002 16:13:23 -0600

We are using Whats Up Gold to monitor network devices and servers.
One of the network devices we are monitoring is beyond our firewall and is
on the same Network as our server running Snort.
We are getting Alerts with the source address as our firewall and the
destination as the network device we are monitoring beyond our firewall.

To make a long story short we are not surprised to see this however we would
like to modify the rule with SID 376 so that when the source is x and the
destination is z -ignore it - otherwise log it.


Thanks, 
Robert Axness 


**********************************************************************
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager.

This footnote also confirms that this email message has been swept by
MIMEsweeper for the presence of computer viruses.

www.mimesweeper.com
**********************************************************************



-------------------------------------------------------
This sf.net email is sponsored by:
With Great Power, Comes Great Responsibility 
Learn to use your power at OSDN's High Performance Computing Channel
http://hpc.devchannel.org/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: