<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cisco IPS reporting in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746679#M56028</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you been performing any analysis on these "attacks"? Are they real or false positives?&lt;/P&gt;&lt;P&gt;If they are real and your attackers and victims are indeed incorrect, you can swap them by editing the signature in question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Oct 2011 18:14:58 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2011-10-18T18:14:58Z</dc:date>
    <item>
      <title>cisco IPS reporting</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746678#M56027</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp; When i genrate top 10 victim report on IPS module&amp;nbsp; on ASA 5520&amp;nbsp; it shows that attacker addresses are my local LAN ip addresses and the&amp;nbsp; victims are public ip address on the internet. I beleive should be the&amp;nbsp; other way around to be the victim are my LAN side.&lt;/P&gt;&lt;P&gt;I have the same in more than on IPS modules for different customers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:31:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746678#M56027</guid>
      <dc:creator>seegomaa</dc:creator>
      <dc:date>2019-03-10T12:31:09Z</dc:date>
    </item>
    <item>
      <title>cisco IPS reporting</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746679#M56028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you been performing any analysis on these "attacks"? Are they real or false positives?&lt;/P&gt;&lt;P&gt;If they are real and your attackers and victims are indeed incorrect, you can swap them by editing the signature in question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 18:14:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746679#M56028</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-10-18T18:14:58Z</dc:date>
    </item>
    <item>
      <title>cisco IPS reporting</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746680#M56029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Bob for your reply.&lt;/P&gt;&lt;P&gt; I believe that it is incorrect because all attackers are from LAN side and zero from outside for around 4 months.&lt;/P&gt;&lt;P&gt;So could you explain to me how to swap this in the signature as you mentioned ? ""Im using GUI interface""&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,,,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Oct 2011 03:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746680#M56029</guid>
      <dc:creator>seegomaa</dc:creator>
      <dc:date>2011-10-19T03:44:53Z</dc:date>
    </item>
    <item>
      <title>cisco IPS reporting</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746681#M56030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using the Java GUI,&lt;/P&gt;&lt;P&gt;Go into the "Configuration" tab, select the "Policies" button (lower left corner)&lt;/P&gt;&lt;P&gt;Expand the tree on the tree in the upper left panel: Signature Definitions, sig0, All Signatures&lt;/P&gt;&lt;P&gt;Select the signature you want to edit.&lt;/P&gt;&lt;P&gt;Scroll about halfway down the list of signature settings to "Swap Attacker Victim", check the box and set the value to "yes". hit "OK" to save this signature and move on to the next signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Oct 2011 15:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-reporting/m-p/1746681#M56030</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-10-19T15:44:40Z</dc:date>
    </item>
  </channel>
</rss>

