On Thu, Dec 12, 2002 at 07:37:29PM -1000, Ben Beeson wrote: > So essentially, snort is seeing a lot of other traffic on my > external interface that is not necessarily destined for my box. > Is that right???
I believe so. I am unable to think of how the destination address can be spoofed without something within the same network participating in the attack. Hmm. -Vince
