<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSA Rule Exception issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719926#M86177</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Adam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it says that in the user guide and I experienced the same thing when doing it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Part of the user guide seems a bit confusing to me though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 1st statement on page 10-22 in the CSA 5.2 User guide is correct: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create a new rule module (an "exception rule module") which &lt;/P&gt;&lt;P&gt;would contain the new exception rule. (This is the default and recommended choice.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 2nd statement is (I feel) incorrect: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"This new module would be attached to a new exception policy which is then&lt;/P&gt;&lt;P&gt;attached to the group(s) containing the host from which the event was received."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've done this several times and have yet to see it create an separate exception policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the 3rd statement is correct:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"If you choose to create this exception module, all subsequent exception rules you&lt;/P&gt;&lt;P&gt;create through the wizard will be added to the same exception module and policy&lt;/P&gt;&lt;P&gt;if the group it is to be applied to is also the same. Therefore, a group could only&lt;/P&gt;&lt;P&gt;have one exception policy, but contain an exception rule module with any number&lt;/P&gt;&lt;P&gt;of exception allow rules created through the wizard."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Jul 2007 15:07:09 GMT</pubDate>
    <dc:creator>tsteger1</dc:creator>
    <dc:date>2007-07-20T15:07:09Z</dc:date>
    <item>
      <title>CSA Rule Exception issue</title>
      <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719920#M86152</link>
      <description>&lt;P&gt;Is it possible when creating an exception with the Rule Wizard to not have it create a new rule module every time a rule is created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I would like to just add rules to an Exceptions policy that is applied to the group with out it creating a new rule module every time.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719920#M86152</guid>
      <dc:creator>kerraj2004</dc:creator>
      <dc:date>2019-03-10T10:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: CSA Rule Exception issue</title>
      <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719921#M86155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is not possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have the choice of a new rule module (the exception module) or add it to the module containing the rule that triggered the event(not recommended).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You just have to go through the wizard, copy where you want it and delete the exception created by the wizard.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 16:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719921#M86155</guid>
      <dc:creator>Bradley Spencer</dc:creator>
      <dc:date>2007-07-19T16:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: CSA Rule Exception issue</title>
      <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719922#M86158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bradley,&lt;/P&gt;&lt;P&gt;I thought so and that is what i have been doing is copying the rule and deleting the other rule module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Adam &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 16:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719922#M86158</guid>
      <dc:creator>kerraj2004</dc:creator>
      <dc:date>2007-07-19T16:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: CSA Rule Exception issue</title>
      <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719923#M86163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I took a slightly different path with CSA 5.2 than I did with 4.0 and I feel it makes less work after creating exceptions with the wizard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The wizard will create only one exception module per rule module and will put all subsequent wizard created exceptions in that module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may conceivably end up with double the number of rule modules if you create exceptions for every module (not very likely) but it keeps them in easily identifiable locations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just my two cents worth..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 19:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719923#M86163</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-07-19T19:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: CSA Rule Exception issue</title>
      <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719924#M86170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So Tom, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically you are saying create a Network Access Control Rule Module one time and then all the exception that pertain to that module will fall underneath that Module automatically?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Adam &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 19:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719924#M86170</guid>
      <dc:creator>kerraj2004</dc:creator>
      <dc:date>2007-07-19T19:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: CSA Rule Exception issue</title>
      <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719925#M86174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The way we do it is by creating an exception policy for each system or group of systems that we want exceptions for then adding the exceptions there.  This is very easy if you make exceptions manually (recommended), but is more difficult if you do it with the crappy wizard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 21:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719925#M86174</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2007-07-19T21:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: CSA Rule Exception issue</title>
      <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719926#M86177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Adam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it says that in the user guide and I experienced the same thing when doing it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Part of the user guide seems a bit confusing to me though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 1st statement on page 10-22 in the CSA 5.2 User guide is correct: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create a new rule module (an "exception rule module") which &lt;/P&gt;&lt;P&gt;would contain the new exception rule. (This is the default and recommended choice.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 2nd statement is (I feel) incorrect: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"This new module would be attached to a new exception policy which is then&lt;/P&gt;&lt;P&gt;attached to the group(s) containing the host from which the event was received."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've done this several times and have yet to see it create an separate exception policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the 3rd statement is correct:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"If you choose to create this exception module, all subsequent exception rules you&lt;/P&gt;&lt;P&gt;create through the wizard will be added to the same exception module and policy&lt;/P&gt;&lt;P&gt;if the group it is to be applied to is also the same. Therefore, a group could only&lt;/P&gt;&lt;P&gt;have one exception policy, but contain an exception rule module with any number&lt;/P&gt;&lt;P&gt;of exception allow rules created through the wizard."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2007 15:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719926#M86177</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-07-20T15:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: CSA Rule Exception issue</title>
      <link>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719927#M86180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like someone has suggested, the proper way to do this is to create your own rule module with execptions, maybe do several based on what policy they belong to or what application it is concerning, then just hit copy the text of the event, hit the rule number, choose the rule, copy to your own rule module and tune it with the info from the event text you just copied. This is how i work with csa, in my eyes the wizard is really just for learning purposes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Jul 2007 10:30:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-rule-exception-issue/m-p/719927#M86180</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2007-07-21T10:30:27Z</dc:date>
    </item>
  </channel>
</rss>

