@dancwilliams:
Ah,
Don't mind me…I see what is happening now. Mark me embarrassed :-.
I do have Suricata installed and doing some testing. I was unaware that Suricata used the snort2c list to block hosts.
Still in learning mode on all that.
Thanks for the help!
Dan
Yes, for expediency when Suricata blocking mode was released, it used the same pre-existing <snort2c>table. That's why you don't want Snort and Suricata both installed and blocking on the same box. It's OK to install both if you really want to, but only one of them should be configured for blocking.
Bill</snort2c>