18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Ignoring network probe attempts<br />

17-18 Alarm Events and Responses<br />

Configuring the ignore list<br />

The data items in the ignore list define the network probe audit<br />

events to ignore. The ignore list is only used by the<br />

netprobe_filter auditbot.<br />

Note: The ignore list is configured in the /etc/sidewinder/auditbotd.conf file.<br />

Important: Packets in the ignore list will still be logged to the audit.raw file.<br />

The netprobe_filter auditbot collects audit data on network probe<br />

attempts occurring on your system, but does not take action on<br />

network probe attempt audit events that match entries in the ignore<br />

list. The ignore list fields read as follows:<br />

ignore(burb protocol src_host src_port dst_host<br />

dst_port)<br />

Unlike the discard service, the ignore list allows you to use wildcards<br />

in all <strong>of</strong> its configured fields. Besides the wildcard, the fields can<br />

contain the following values:<br />

burb<br />

0 through 24 or the wildcard “*”<br />

protocol<br />

A numerical protocol, a protocol name from /etc/protocols (such as<br />

udp or tcp), or “*”.<br />

src_host and dst_host<br />

A host name, a dotted IP address, or an asterisk (*) representing<br />

the source or destination host.<br />

Note: IP addresses cannot be sub-wildcarded, (that is, dotted IP addresses are valid<br />

only as a full IP address or asterisk [*] with no rule-type wildcarding).<br />

src_port and dst_port<br />

A numerical port number, a service name from /etc/services, or an<br />

asterisk (*) represents the source or destination port<br />

The <strong>Sidewinder</strong> <strong>G2</strong> contains the following default ignore list entry to<br />

disregard ident probes from all sources:<br />

ignore (* tcp * * * ident)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!