On Thu, 7 Sep 2006 07:27:16 -0400
"Mike Walter" <mwalter@3z.net> wrote:
Sep 7 06:50:20.697 EST: %SEC-6-IPACCESSLOGP: list 166 denied tcp
69.50.222.8(25) -> 69.4.74.14(2421), 4 packets
[...]
I'm not very familiar with NBAR or how to use it for CodeRed, but this
first rule:
access-list 166 deny ip any any dscp 1 log
Seems dubious. So I'm not not sure what sets the codepoint to 000001
by default, but apparently CodeRed does? Nevertheless, this seems like
a very weak basis for determining whether something is malicious.
It's his NBAR config lower down that sets the dscp value: