<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Actions Occuring That Are Not Assigned in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457001#M66710</link>
    <description>&lt;P&gt;I noticed this morning that a custom signature I created triggered and an action that I didn't assign to it occured.&amp;nbsp; I set the severity to medium and the actions of the signature to alarm and deny packet inline but "denied flow" also shows as an action taken in the alert message.&amp;nbsp; I have two event action overrides, but they are set to add produce alert (medium) and produce alert and deny packet inline (high). I tried rebooting the sensor and then triggered the alert and it did the same thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not a major issue, but I do find it kind of odd.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPS is an ASA-SSM-20 running 7.0(4)E4.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:06:08 GMT</pubDate>
    <dc:creator>terrygwazdosky</dc:creator>
    <dc:date>2019-03-10T12:06:08Z</dc:date>
    <item>
      <title>Actions Occuring That Are Not Assigned</title>
      <link>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457001#M66710</link>
      <description>&lt;P&gt;I noticed this morning that a custom signature I created triggered and an action that I didn't assign to it occured.&amp;nbsp; I set the severity to medium and the actions of the signature to alarm and deny packet inline but "denied flow" also shows as an action taken in the alert message.&amp;nbsp; I have two event action overrides, but they are set to add produce alert (medium) and produce alert and deny packet inline (high). I tried rebooting the sensor and then triggered the alert and it did the same thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not a major issue, but I do find it kind of odd.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPS is an ASA-SSM-20 running 7.0(4)E4.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:06:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457001#M66710</guid>
      <dc:creator>terrygwazdosky</dc:creator>
      <dc:date>2019-03-10T12:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Actions Occuring That Are Not Assigned</title>
      <link>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457002#M66711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's weird. Can you paste the details of the custom signature you have created?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Aug 2010 15:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457002#M66711</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-23T15:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Actions Occuring That Are Not Assigned</title>
      <link>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457003#M66713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;signatures 60000 0 &lt;BR /&gt;alert-severity medium&lt;BR /&gt;sig-fidelity-rating 75&lt;BR /&gt;sig-description&lt;BR /&gt;sig-name MS10-046&lt;BR /&gt;sig-string-info .pif or .lnk file extension matching&lt;BR /&gt;&lt;SPAN&gt;sig-comment &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.microsoft.com/technet/security/bulletin/MS10-046.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/MS10-046.mspx&lt;/A&gt;&lt;BR /&gt;exit&lt;BR /&gt;engine service-http&lt;BR /&gt;event-action produce-alert|deny-packet-inline&lt;BR /&gt;regex&lt;BR /&gt;specify-uri-regex yes&lt;BR /&gt;uri-regex \.([Ll][Nn][Kk]|[Pp][Ii][Ff])&lt;BR /&gt;exit&lt;BR /&gt;exit&lt;BR /&gt;service-ports 80,8080&lt;BR /&gt;exit&lt;BR /&gt;event-counter&lt;BR /&gt;event-count 1&lt;BR /&gt;event-count-key Axxx&lt;BR /&gt;specify-alert-interval no&lt;BR /&gt;exit&lt;BR /&gt;alert-frequency&lt;BR /&gt;summary-mode fire-once&lt;BR /&gt;exit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Aug 2010 15:37:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457003#M66713</guid>
      <dc:creator>terrygwazdosky</dc:creator>
      <dc:date>2010-08-23T15:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Actions Occuring That Are Not Assigned</title>
      <link>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457004#M66715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The action taken by the sensor for a TCP-based signature with 'deny packet inline' action will be "upgraded" automatically to 'deny connection inline'.&amp;nbsp; This is by design of the software.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Aug 2010 15:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/actions-occuring-that-are-not-assigned/m-p/1457004#M66715</guid>
      <dc:creator>cvilleme</dc:creator>
      <dc:date>2010-08-23T15:43:49Z</dc:date>
    </item>
  </channel>
</rss>

