Allright I changed the threshold in my conf file. That seems to have stopped it without affecting detection of real portscans, or at least the one I've run from pcflank.com as well as my own Nmap scans. Hopefully there will be no reoccurence <grits teeth>




Reply With Quote