Snort drops the incoming HTTP response packets

Tamás Németh via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAKrH-T+u4Ydtsht=Cwb9ecoL2_4Df7wyvL_NABX4_nSXhu-=hA@mail.gmail.com>
Dear All!

 I face the problem that snort drops the incoming HTTP response packets
from a certain unencrypted HTTP website, but it does not log the
dropping event in /var/log/snort/alert , so I have no idea, which rule is
responsible (if a rule does in anyway). I'm using the registered
rules snortrules-snapshot-29200.tar.gz , and the website is http://mekh.hu

 How could I figure out the reason of snort to drop these packets.

Thank you in advance,

Tamás Németh
IT sysadmin
Waterworks of Sopron, Hungary

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.