Jim Cheetham wrote:
On Wed, Oct 15, 2008 at 10:00 PM, <[EMAIL PROTECTED]> wrote:
I've got a 7.8mb secure log with this stuff in it and not sure what I should
do to sort it out?
[EMAIL PROTECTED] log]# tail -f secure
Oct 15 21:06:41 bowenvale snort[21511]: [1:1620:5] BAD TRAFFIC Non-Standard
IP protocol [Classification: Detection of a non-standard protocol or event]
[Priority: 2]: {UDP} 203.96.152.4:53 -> 121.73.114.171:58076
Errm, respectfully, if you don't know what this stuff is, don't run snort.
It isn't a user-level piece of software, it's a network intrusion
detection/prevention system. If it isn't configured to fit your
network, it'll cause problems for you ...
-jim
It's all packaged with clark connect and seems to be working ok. It's
got preaty flash stuff that shows me I've got over 80k hits from one IP
alone in the last day.
I've emailed [EMAIL PROTECTED] to see if they can block the
traffic.
Cheers Don
--
Don Gould
31 Acheson Ave, Mairehau, Christchurch, NZ
Ph +64 3 348 7235 or + 64 21 114 0699
www.thinkdesignprint.co.nz