LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-30-2005, 02:03 AM   #1
zahra79
LQ Newbie
 
Registered: Apr 2005
Posts: 13

Rep: Reputation: 0
a problem with snort .(port in servers)


hi
i have a question about snort .i am very confused
may you help me please .
my problem is :
i have a mail server(mail server ip=62.60.183.20 ) in my network and i
wrote a rule same as:
alert tcp any any -> 62.60.183.20 !25
when i run snort a see alerts in my network same as :

07/26-22:09:53.036073 213.217.12.42:25 -> 62.60.183.20:58697
TCP TTL:55 TOS:0x0 ID:15871 IpLen:20 DgmLen:74 DF
***AP*** Seq: 0x64ECE01A Ack: 0xCC8E10E3 Win: 0xE070 TcpLen: 32
TCP Options (3) => NOP NOP TS: 433629700 94532431

i have many of this alerts.
i can not underestand what happend.
why client's port is 25 .
do this packet is intrusion??
i have this problem with all of my servers in network.
how can i fix it??
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Snort , quit logging that port! stakhous Linux - Security 0 12-08-2004 04:37 PM
im not unning any servers, but i do have open ports.. is snort usefull ? qwijibow Linux - Security 0 10-24-2004 02:43 PM
snort logging all outbound traffic as port-scan? Pcghost Linux - Security 3 04-20-2004 01:12 PM
snort and proxy servers zuessh Linux - Security 8 03-08-2004 06:41 PM
Snort, FIN Scans, and port 6346 (Gnutella) green_dragon37 Linux - Security 2 11-17-2003 08:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration