Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 3.14 What the heck Up: 3 Configuring Snort Previous: 3.12 How do you

3.13 Why does the portscan plugin log ``stealth'' packets even though the host is in the portscan-ignorehosts list?

These types of tcp packets are inherently suspicious, no matter where they are coming from. The portscan detector was built with the assumption that stealth packets should be reported, even from hosts which are not monitored for portscanning. An option to ignore ``stealth'' packets may be added in the future.



Nigel Houghton 2006-10-02