Hi, Currently seeing an abnormal amount of http traffic consisting of only tcp syn packets according to snort.
My main question is how can I block inbound traffic from a given host using arp? Related question: I've added block rules for the offending hosts in my ipf rule list, but snort still sees traffic from these hosts after restarting ipf to include the new block rules - why is this? TIA -- Jez Hancock - System Administrator / PHP Developer http://munk.nu/ _______________________________________________ [EMAIL PROTECTED] mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to "[EMAIL PROTECTED]"