maybe setup an acl for port range 137 to 139 with log
then check on the logg

On Fri, Feb 5, 2010 at 10:34 PM, Imran K <[email protected]> wrote:

> As stated by other posters, the best "passive" way to determine this is via
> stack operations. ( sequencing, etc ), which is best done "off router" due
> to the specific nature ( active ).
>
> Is it not possible to write a custom IDS signature that will analyse
> similar
> footprints ( passively ) as nmap.
> _______________________________________________
> cisco-nsp mailing list  [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to