pita
05-06-2002, 10:19 AM
I have just begun running snort on a *nix box that we use as a webserver. We're getting 1000's of alerts logged for netbios name queries.
Should I just comment that rule out of the snort rule set cuz it's a *nix box and it won't respond to netbios name requests anyway
- or -
Add a rule to our firewall to just block netbios name queries
?
Thanks,
Pita
Should I just comment that rule out of the snort rule set cuz it's a *nix box and it won't respond to netbios name requests anyway
- or -
Add a rule to our firewall to just block netbios name queries
?
Thanks,
Pita
