Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Third Party Tools » Port Scans not detected

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Port Scans not detected


Posted by jerumball on May 03, 2005 20:38:26

I have recently installed Snort, ACID, PHP, MYSQL on my FC2 system, using an instructional guide from Patrick Harper. I should mention that this box is my home firewall, running Firestarter to manage iptables.

It seems to working OK (i.e. I can browse to web interface and see various events) but when I tried to use the Shields UP service at www.grc.com, Snort did not detect a port scan or even an ICMP from that site!

Can someone please explain what I might be doing wrong? Snort is detecting events with sources on both sides of the firewall, but in the past month or so that it has been running, it has detected only 9 unique events.

Thanks, in advance.

John