<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dealing with False Positive alerts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122170#M79092</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;4500 UDP is for VPN tunnels.  It is often a false positive for what you referenced.  Just create Flase Postive event for the two hosts and tune it to log to DB only if you are using CSMARS, and I think it has already been answered for the IPS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Aug 2008 19:31:15 GMT</pubDate>
    <dc:creator>mdreelan</dc:creator>
    <dc:date>2008-08-21T19:31:15Z</dc:date>
    <item>
      <title>Dealing with False Positive alerts</title>
      <link>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122167#M79088</link>
      <description>&lt;P&gt;I have hits on a BO2K-UDP signature.  I looked up the ip address on Arin and it is from a company that we would probably do business with.  Using nmap, I fingerprinted the remote server and it appears to be a standard MS Web/Mail server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I tell IPS to ignore the host while paying attention to the rule ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122167#M79088</guid>
      <dc:creator>Ronald Nutter</dc:creator>
      <dc:date>2019-03-10T11:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Dealing with False Positive alerts</title>
      <link>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122168#M79089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Set up an Event Action Filter to subtract the action of producing an alert when the alert includes for instance from attacker ip on port 4500 to this victim ip on port 4500 and the reverse&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if that's what you're asking but I hope that helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 22:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122168#M79089</guid>
      <dc:creator>genewolfe</dc:creator>
      <dc:date>2008-08-20T22:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dealing with False Positive alerts</title>
      <link>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122169#M79091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do the 'event action filter' bit only if you are seeing this event numerous times. Occasionally any web client (browser) could choose the source port 4500 at random. The returning traffic from the web server to the client on port 4500 is consider BO2K by the IPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2008 01:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122169#M79091</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-21T01:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dealing with False Positive alerts</title>
      <link>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122170#M79092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;4500 UDP is for VPN tunnels.  It is often a false positive for what you referenced.  Just create Flase Postive event for the two hosts and tune it to log to DB only if you are using CSMARS, and I think it has already been answered for the IPS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2008 19:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dealing-with-false-positive-alerts/m-p/1122170#M79092</guid>
      <dc:creator>mdreelan</dc:creator>
      <dc:date>2008-08-21T19:31:15Z</dc:date>
    </item>
  </channel>
</rss>

