A couple of questions
Gustaf Florén via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CADkpq3subkT3exWOVXEfapzKAnLBSqjUbNZ70LJZT-zrABDaew@mail.gmail.com> |
Hi
I have a couple of questions.
1. I have active module set to active ={ attempts=2 }
What is the default nr of packets sent per response if active module is not
set??
Is it safe to remove active module all together and rely on reject module
only?
2.Are there rules in community ruleset that are not in registered rules?
3.I have rule below to block xmas scans, but it doesnt work, snort only
notices the scan but not blocking it.How can I block xmas scans??
reject tcp any any -> $HOME_NET any ( msg:"xmas"; flags:FPU; sid:1; )
Gustaf
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette