<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are there something wrong with attackers? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/are-there-something-wrong-with-attackers/m-p/980135#M79595</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't provide enough details (what sig is firing), but it is perfectly normal for an untuned IDS/IPS to have thousands of false positives, many of which will be sourced from your own network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should create an event action filter that has your network space as a source and add any signatures that are false positives.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Jul 2008 11:48:53 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2008-07-02T11:48:53Z</dc:date>
    <item>
      <title>Are there something wrong with attackers?</title>
      <link>https://community.cisco.com/t5/network-security/are-there-something-wrong-with-attackers/m-p/980133#M79593</link>
      <description>&lt;P&gt;When I look at the events I see %95 of the attackers from my inside network. Is it wrong or is it normal? Shouldnt I see the attackers from outside real ips?&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-there-something-wrong-with-attackers/m-p/980133#M79593</guid>
      <dc:creator>blackswans</dc:creator>
      <dc:date>2019-03-10T11:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Are there something wrong with attackers?</title>
      <link>https://community.cisco.com/t5/network-security/are-there-something-wrong-with-attackers/m-p/980134#M79594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In firewall case you can not check the real ip because the outside ip may be spoofed . Some time it may be real when some hackers wants to touch your network from their public domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my suggestion just imply the Reject rule in this case user can not touch your interface and you will be safe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shridhar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2008 10:03:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-there-something-wrong-with-attackers/m-p/980134#M79594</guid>
      <dc:creator>shridhar76</dc:creator>
      <dc:date>2008-07-02T10:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Are there something wrong with attackers?</title>
      <link>https://community.cisco.com/t5/network-security/are-there-something-wrong-with-attackers/m-p/980135#M79595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't provide enough details (what sig is firing), but it is perfectly normal for an untuned IDS/IPS to have thousands of false positives, many of which will be sourced from your own network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should create an event action filter that has your network space as a source and add any signatures that are false positives.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2008 11:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-there-something-wrong-with-attackers/m-p/980135#M79595</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-07-02T11:48:53Z</dc:date>
    </item>
  </channel>
</rss>

