Netbios name query
I have just begun running snort on a *nix box that we use as a webserver. We're getting 1000's of alerts logged for netbios name queries.Should I just comment that rule out of the snort rule set cuz it's a *nix box and it won't respond to netbios name requests anyway
- or -
Add a rule to our firewall to just block netbios name queries
?
Thanks,
Pita