Snort mailing list archives

RE: RE: Attack on snort running in Public Zone


From: james <jamesh () cybermesa com>
Date: 16 Nov 2003 01:11:43 -0700

On Sun, 2003-11-16 at 00:44, james wrote:
 Since this box only needs to listen
to the mirror port, drop all traffic from the internet to this box, on
the next hop router.


For the management interface, that is. IP unnumbered
is the way to go.
 






Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: