<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: signature triggering in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904119#M85093</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, they both get triggered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-brad &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ccbootcamp.com" target="_blank"&gt;www.ccbootcamp.com&lt;/A&gt; &lt;/P&gt;&lt;P&gt;(please rate the post if this helps!) &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Dec 2007 10:10:46 GMT</pubDate>
    <dc:creator>ccbootcamp</dc:creator>
    <dc:date>2007-12-15T10:10:46Z</dc:date>
    <item>
      <title>signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904118#M85089</link>
      <description>&lt;P&gt;If the conditions match two signatures, do they both get triggered or only the first one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:54:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904118#M85089</guid>
      <dc:creator>mai2mai2m</dc:creator>
      <dc:date>2019-03-10T10:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904119#M85093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, they both get triggered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-brad &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ccbootcamp.com" target="_blank"&gt;www.ccbootcamp.com&lt;/A&gt; &lt;/P&gt;&lt;P&gt;(please rate the post if this helps!) &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Dec 2007 10:10:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904119#M85093</guid>
      <dc:creator>ccbootcamp</dc:creator>
      <dc:date>2007-12-15T10:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904120#M85100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In CISCO IPS, can we wrtie a 'pass' rule to ignore good traffic and prevent it from trigger other signatures that cannot be turned off?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2007 13:08:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904120#M85100</guid>
      <dc:creator>mai2mai2m</dc:creator>
      <dc:date>2007-12-17T13:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904121#M85105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you should be able to use an event action filter for this purpose. You can create a filter and put it at the top and set it to "stop on match".  You can match on signature, ip address, port, and risk.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2007 14:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904121#M85105</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-12-17T14:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904122#M85111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your responding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, looks like the CISCO wizard only allows to filter based on signature ID, ip, port, and risk. Is it poosible to filter on other fields in the header or payload?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2007 19:20:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904122#M85111</guid>
      <dc:creator>mai2mai2m</dc:creator>
      <dc:date>2007-12-17T19:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904123#M85114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Brad. Regarding the "both triggered", would there be any CISCO document I can refer to?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2007 19:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904123#M85114</guid>
      <dc:creator>mai2mai2m</dc:creator>
      <dc:date>2007-12-17T19:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904124#M85117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can only filter on those things. You can however create a custom signature that matches on something in the payload and then create a filter that subtracts all actions and has a "stop on match".  If the signature matches every packet, then this should work quite well (we do it in fact).  If the signature matches only one packet of many [in a stream you want to guarantee no alarms for] I'm not sure that it will work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2007 19:31:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904124#M85117</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-12-17T19:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904125#M85119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, don't forget, when you do the custom event and enable "stop on match" you also MUST SELECT the actions you do NOT want to happen! A lot of people miss that step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-brad&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ccbootcamp.com" target="_blank"&gt;www.ccbootcamp.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(please rate the post if this helps!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2007 19:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904125#M85119</guid>
      <dc:creator>ccbootcamp</dc:creator>
      <dc:date>2007-12-17T19:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: signature triggering</title>
      <link>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904126#M85121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll confirm Brad's post.  We will trigger all alerts whose conditions are met by a packet or stream.  We do not "fire first and forget"...that is a recipe for evasion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be aware that in a stream signature, what has come before affects what happens in the present.  We are analyzing the "stream"...not just the "packet".  I mention this so that you can be aware that just because a particular condition exists in a packet, a signature may not fire because of something that was present (or not present) in a previous packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2007 15:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-triggering/m-p/904126#M85121</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2007-12-18T15:59:30Z</dc:date>
    </item>
  </channel>
</rss>

