[ previous ] [ next ] [ threads ]
 From:  "Fady Makar" <fady dot makar at mapds dot com dot au>
 To:  "'Avenger 2.0'" <info at hyperdrive dot be>, "'m0n0wall list'" <m0n0wall at lists dot m0n0 dot ch>
 Subject:  RE: [m0n0wall] Re: Generic PC Version - m0n0 1.1b17 + snort
 Date:  Fri, 1 Oct 2004 15:04:48 +1000
Hi All,

So how come the Snort feature didn't continue with the latest versions
of M0n0Wall, I thought it was good feature to have. Particularly with
the auto updates for it form the Web....



-----Original Message-----
From: Avenger 2.0 [mailto:info at hyperdrive dot be] 
Sent: Sunday, 22 August 2004 6:52 PM
To: m0n0wall list
Subject: [m0n0wall] Re: Generic PC Version - m0n0 1.1b17 + snort

I did some portscan tests from various sites, but Snort will not detect
scans or even trojan port scans (even with all rules enabled). You can 
clearly see all the blocked requests in the Firewall log but only icmp
are logged with Snort Log.
Is this normal behaviour from Snort or is there something wrong with
Snort in m0n0wall?


> The links:
> http://xoomer.virgilio.it/ortaj/m0n0/pc-generic-1.1b17-snort.img.gz
> http://xoomer.virgilio.it/ortaj/m0n0/wrap-1.1b17-snort.gz
> http://xoomer.virgilio.it/ortaj/m0n0/cd-1.1b17-snort.iso.gz

To unsubscribe, e-mail: m0n0wall dash unsubscribe at lists dot m0n0 dot ch
For additional commands, e-mail: m0n0wall dash help at lists dot m0n0 dot ch