Hello, can I see the configuration of IDS/IPS Snort, wich is used in clearOS? And how to do it?
Share this post:
Responses (4)
-
Accepted Answer
Dirk Albring wrote:
I can't see the parameter "FTP_PORTS" used anywhere. In the "FTP / Telnet normalization and anomaly detection" the ports are again restricted to 21, 2100 and 3535. In the rules, they are all hardcoded with 21, so no 2121 or 990. If there is a bug to be filed, it would extend FTP_PORTS to cover 2121 and 989/990 and to change the ClearCenter ftp rules from 21 to $FTP_PORTS.
Hmm, this thread peaked my curiosity. Looked at my snort.conf and noticed 2121 wasn't included in the ftp ports. Am I missing something or is that just an oversight?
-
Accepted Answer

Please login to post a reply
You will need to be logged in to be able to post a reply. Login using the form on the right or register an account if you are new here.
Register Here »