Snort won't do that without the fairly experimental active response piece.
ISS RealSecure will do it with an RSKill, which we started doing a few hours ago. ------------------------------------------------------ Roger D. Seielstad - MCSE MCT Senior Systems Administrator Peregrine Systems Atlanta, GA http://www.peregrine.com > -----Original Message----- > From: Byron Kennedy [mailto:[EMAIL PROTECTED]] > Sent: Tuesday, December 04, 2001 2:18 PM > To: Exchange Discussions > Subject: RE: New Virus outbreak - OT on snort > > > yes. do you have a rule that is catching gone_A and pulling > the frames off the wire? > > -----Original Message----- > From: Koos Jacobs [mailto:[EMAIL PROTECTED]] > Sent: Tuesday, December 04, 2001 10:39 AM > To: Exchange Discussions > Subject: RE: New Virus outbreak > > > Don't you guys use an Intrusion Detection > Package......something like Snort??? > > _________________________________________________________________ > List posting FAQ: http://www.swinc.com/resource/exch_faq.htm > Archives: http://www.swynk.com/sitesearch/search.asp > To unsubscribe: mailto:[EMAIL PROTECTED] > Exchange List admin: [EMAIL PROTECTED] > > _________________________________________________________________ > List posting FAQ: http://www.swinc.com/resource/exch_faq.htm > Archives: http://www.swynk.com/sitesearch/search.asp > To unsubscribe: mailto:[EMAIL PROTECTED] > Exchange List admin: [EMAIL PROTECTED] > _________________________________________________________________ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Archives: http://www.swynk.com/sitesearch/search.asp To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin: [EMAIL PROTECTED]