Snort mailing list archives

var HTTP_PORTS and new rules


From: Erik Nyman <m9520 () abc se>
Date: Tue, 18 Nov 2003 13:06:55 +0100 (MET)

Hi!

I have installed snort on RH 9 and it's up and running just fine.

I have two basic questions.

1. I got a lot of FP on 8080, and I can't figure it out how to fix it.
We have internal webservers that run on port 80, and mainly all other
traffic goes through a proxy on port 8080. You can't set [80,8080]
like you do for networks, just a range like 80:8080.

2. How often should I download new rules? Because I edit in the rules
to get rid of a lot of FP, but maybe there is a better way to do that.
Is there a possibillity to have the exclusions in a separate file?

------------------

Erik Nyman
eny () abc se


-------------------------------------------------------
This SF. Net email is sponsored by: GoToMyPC
GoToMyPC is the fast, easy and secure way to access your computer from
any Web browser or wireless device. Click here to Try it Free!
https://www.gotomypc.com/tr/OSDN/AW/Q4_2003/t/g22lp?Target=mm/g22lp.tmpl
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: