You have to look at the rules currently loaded. I don't think simply
telneting will set off an alert and therefore drop. You would have to
look at the rules. Or you can generate a drop rule that will drop
outbound tcp 23 to test the theory if you want.
Rob
On Feb 27, 2008, at 2:10 PM, Nandhini Thiagarajan wrote:
Yes attempting a telnet connection, i thought should be disabled by
Snort Inline and record the logs. Is that rite?
Robert Mcmillen <[EMAIL PROTECTED]> wrote:
Did you do something that would trigger a snort_inline rule?
Rob
On Feb 27, 2008, at 1:48 PM, Nandhini Thiagarajan wrote:
Hello,
I dont find any Snort_Inline logs in Honeywall roo 1.2.
I initiated a ssh connection to my honeypot and through that tried
to telnet to one of the prodcution systems.
For the above connections, i dont see any snort_Inline logs?
I dont think this is correct.
May be i'm doing something incorrect. Can somebody help?
Thanks
Nandhini
Looking for last minute shopping deals? Find them fast with Yahoo!
Search._______________________________________________
Honeywall mailing list
[email protected]
https://public.honeynet.org/mailman/listinfo/honeywall
Never miss a thing. Make Yahoo your homepage.
_______________________________________________
Honeywall mailing list
[email protected]
https://public.honeynet.org/mailman/listinfo/honeywall