[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] portsentry - config changes, help needed.









From: Gerald Waugh <gwaugh@xxxxxxxxxxxxxxxxxxxxxxx>
Reply-To: cobalt-users@xxxxxxxxxxxxxxx
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: Re: [cobalt-users] portsentry - config changes, help needed.
Date: Fri, 17 Jan 2003 06:44:07 -0500 (EST)

On Fri, 17 Jan 2003, cobalt raq4 wrote:
>
> I have made a few changes to the default config in portsentry, removed a
> couple of ports from the 'Port Configuration' section as I am tired of
> logcheck sending me 'Active System Attack' heading that can not be ignored.
>
> I have killed the two processes that were running for portsentry and
> restarted them again yet I am still receiving reports for scans on the
> unwanted ports.
>
> /usr/local/psionic/portsentry/portsentry -tcp
> /usr/local/psionic/portsentry/portsentry -udp
>
> Can anyone tell me how to restart portsentry so it takes changes to the
> config file into configuration?
>
It looks like you did the correct thing.
Are you sure you removed the port from the correct 'set' of config
parameters. (there are 3 'sets' in there)

Definately from the correct set as I left the 3 default as they were and created a new set for our specific needs. I'm a bit stumped, off to check out the ipchains theory.

Thanks Gerald
MJM

Are you sure that it is portsentry logging the accesses.
maybe ipchains?

Gerald
--
http://frontstreetnetworks.com | http://store.raqware.com
Front Street Networks LLC      | Phone: +1 203 785-0699
229 Front Street, Ste. #C, New Haven, CT. 06513-3203

_____________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To subscribe/unsubscribe, or to SEARCH THE ARCHIVES, go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users


_________________________________________________________________
MSN 8: advanced junk mail protection and 2 months FREE*. http://join.msn.com/?page=features/junkmail