<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS SNMP alarms in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-snmp-alarms/m-p/1418495#M68100</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I also miss syslog in Cisco IPS. But your problem is solvable. You can use Event Action Overrides for set added action (SNMP trap) to all alarm which reach specific risk (maybe high risk, or medium risk, or low risk, or user defined risk as you need). Value "Informational" is not risk value, it is severity (only one part of risk value).&lt;/P&gt;&lt;P&gt;Deny packet inline is usable only in inline mode. This action drop packet which is triggered by specific signature. You can use only TCP reset action to stop some kind of attack in promiscious mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Jan 2010 07:32:35 GMT</pubDate>
    <dc:creator>jan.odzgan</dc:creator>
    <dc:date>2010-01-25T07:32:35Z</dc:date>
    <item>
      <title>IPS SNMP alarms</title>
      <link>https://community.cisco.com/t5/network-security/ips-snmp-alarms/m-p/1418494#M68099</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question concerns the way to send SNMP traps as an alert format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am totally aware that the AIP-SSM/IPS 4200 does not support syslog as an alert format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default method is through SDEE but I really don't want to use MARS to get my security events (I have more than 10 devices so don't think about IME &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'e read that I have to configure individual signatures in order to generate a SNMP trap as an action to take when they are triggered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So is this correct?:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/0/3/8/2830-snmp-1.png" alt="snmp-1.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to enable it "globally"? For example for all signatures with a level higher than informational? Is it done with this option? :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/3/8/2831-snmp-2.png" alt="snmp-2.png" class="jive-image-thumbnail jive-image" height="553" onclick="" width="518" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the first action "deny packet inline"? Is it really done because I am using the AIP-SSM in promiscuous mode...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-snmp-alarms/m-p/1418494#M68099</guid>
      <dc:creator>jacques_henry696</dc:creator>
      <dc:date>2019-03-10T11:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPS SNMP alarms</title>
      <link>https://community.cisco.com/t5/network-security/ips-snmp-alarms/m-p/1418495#M68100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I also miss syslog in Cisco IPS. But your problem is solvable. You can use Event Action Overrides for set added action (SNMP trap) to all alarm which reach specific risk (maybe high risk, or medium risk, or low risk, or user defined risk as you need). Value "Informational" is not risk value, it is severity (only one part of risk value).&lt;/P&gt;&lt;P&gt;Deny packet inline is usable only in inline mode. This action drop packet which is triggered by specific signature. You can use only TCP reset action to stop some kind of attack in promiscious mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jan 2010 07:32:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-snmp-alarms/m-p/1418495#M68100</guid>
      <dc:creator>jan.odzgan</dc:creator>
      <dc:date>2010-01-25T07:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPS SNMP alarms</title>
      <link>https://community.cisco.com/t5/network-security/ips-snmp-alarms/m-p/1418496#M68101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;You can use Event Action Overrides for set added action (SNMP trap) to all alarm which reach specific risk (maybe high risk, or medium risk, or low risk, or user defined risk as you need).&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you're talking about the "Event Action Overrides", are you referring to the second screenshot I've posted? In this configuration, all enabled signatures should trigger a SNMP trap, right? (even if I didn't set the "request SNMP trap" option in all signatures?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Deny packet inline is usable only in inline mode. This action drop packet which is triggered by specific signature. You can use only TCP reset action to stop some kind of attack in promiscious mode.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes that's what I thought. But this action (Deny packet inline) is not removable from the HIGHRISK. So it is not taken into account when using the IPS in promicuous mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jan 2010 11:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-snmp-alarms/m-p/1418496#M68101</guid>
      <dc:creator>jacques_henry696</dc:creator>
      <dc:date>2010-01-27T11:49:42Z</dc:date>
    </item>
  </channel>
</rss>

