Netbios name query

I have just begun running snort on a *nix box that we use as a webserver. We're getting 1000's of alerts logged for netbios name queries.

Should I just comment that rule out of the snort rule set cuz it's a *nix box and it won't respond to netbios name requests anyway

- or -

Add a rule to our firewall to just block netbios name queries

?

Thanks,

Pita

 

 

 

 

Top