You have to look at the rules currently loaded. I don't think simply telneting will set off an alert and therefore drop. You would have to look at the rules. Or you can generate a drop rule that will drop outbound tcp 23 to test the theory if you want.

Rob

On Feb 27, 2008, at 2:10 PM, Nandhini Thiagarajan wrote:

Yes attempting a telnet connection, i thought should be disabled by Snort Inline and record the logs. Is that rite?

Robert Mcmillen <[EMAIL PROTECTED]> wrote:
Did you do something that would trigger a snort_inline rule?

Rob
On Feb 27, 2008, at 1:48 PM, Nandhini Thiagarajan wrote:

Hello,

I dont find any Snort_Inline logs in Honeywall roo 1.2.

I initiated a ssh connection to my honeypot and through that tried to telnet to one of the prodcution systems.

For the above connections, i dont see any snort_Inline logs?
I dont think this is correct.

May be i'm doing something incorrect. Can somebody help?

Thanks
Nandhini

Looking for last minute shopping deals? Find them fast with Yahoo! Search._______________________________________________
Honeywall mailing list
[email protected]
https://public.honeynet.org/mailman/listinfo/honeywall



Never miss a thing. Make Yahoo your homepage.

_______________________________________________
Honeywall mailing list
[email protected]
https://public.honeynet.org/mailman/listinfo/honeywall

Reply via email to