Snort won't do that without the fairly experimental active response piece.

ISS RealSecure will do it with an RSKill, which we started doing a few hours
ago.

------------------------------------------------------
Roger D. Seielstad - MCSE MCT
Senior Systems Administrator
Peregrine Systems
Atlanta, GA
http://www.peregrine.com


> -----Original Message-----
> From: Byron Kennedy [mailto:[EMAIL PROTECTED]] 
> Sent: Tuesday, December 04, 2001 2:18 PM
> To: Exchange Discussions
> Subject: RE: New Virus outbreak - OT on snort
> 
> 
> yes.  do you have a rule that is catching gone_A and pulling 
> the frames off the wire?
> 
> -----Original Message-----
> From: Koos Jacobs [mailto:[EMAIL PROTECTED]]
> Sent: Tuesday, December 04, 2001 10:39 AM
> To: Exchange Discussions
> Subject: RE: New Virus outbreak
> 
> 
> Don't you guys use an Intrusion Detection 
> Package......something like Snort???
> 
> _________________________________________________________________
> List posting FAQ:       http://www.swinc.com/resource/exch_faq.htm
> Archives:               http://www.swynk.com/sitesearch/search.asp
> To unsubscribe:         mailto:[EMAIL PROTECTED]
> Exchange List admin:    [EMAIL PROTECTED]
> 
> _________________________________________________________________
> List posting FAQ:       http://www.swinc.com/resource/exch_faq.htm
> Archives:               http://www.swynk.com/sitesearch/search.asp
> To unsubscribe:         mailto:[EMAIL PROTECTED]
> Exchange List admin:    [EMAIL PROTECTED]
> 

_________________________________________________________________
List posting FAQ:       http://www.swinc.com/resource/exch_faq.htm
Archives:               http://www.swynk.com/sitesearch/search.asp
To unsubscribe:         mailto:[EMAIL PROTECTED]
Exchange List admin:    [EMAIL PROTECTED]

Reply via email to