<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating Event Action Filters  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699848#M87190</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok .. see I really do need a reference. If I am understanding everything right, What I did and what is recommended are the same thing other than the recommendation is using specific victim addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that every network is different and there will probably not be a definate list but what about the type of thinks to look for when tuning a new sensor? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brent &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Mar 2007 15:12:32 GMT</pubDate>
    <dc:creator>bberry</dc:creator>
    <dc:date>2007-03-21T15:12:32Z</dc:date>
    <item>
      <title>Creating Event Action Filters</title>
      <link>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699847#M87189</link>
      <description>&lt;P&gt;Does anyone have a reference for understanding how to create Event Action Filters? I had a filter in place to remove the false positives created by my Proxy servers and the rule has disappeared. I still have the $HTTP_PROXY variable just no rule. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a filter to subtract the Produce Alert Action from the 3030 Signature ID matching the $HTTP_PROXY attacker address and keeping the generic victim address". It seems to be working but I am not sure if that is the correct way. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also been given recommendations that this is not correct and should use one of the following... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my test filter I created without the stop on match checked&lt;/P&gt;&lt;P&gt;service event-action-rules rules0&lt;/P&gt;&lt;P&gt;variables HTTP_Proxy address 172.16.4.72,206.197.1.3&lt;/P&gt;&lt;P&gt;overrides produce-alert &lt;/P&gt;&lt;P&gt;override-item-status Enabled&lt;/P&gt;&lt;P&gt;risk-rating-range 0-100&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;filters edit TcpSynSweep &lt;/P&gt;&lt;P&gt;signature-id-range 3030&lt;/P&gt;&lt;P&gt;attacker-address-range $HTTP_Proxy&lt;/P&gt;&lt;P&gt;victim-address-range 1.1.1.1&lt;/P&gt;&lt;P&gt;actions-to-remove produce-alert&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;filters move TcpSynSweep begin &lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the test filter with the stop on match checked&lt;/P&gt;&lt;P&gt;service event-action-rules rules0      &lt;/P&gt;&lt;P&gt;variables HTTP_Proxy address 172.16.4.72,206.197.1.3&lt;/P&gt;&lt;P&gt;overrides produce-alert &lt;/P&gt;&lt;P&gt;override-item-status Enabled&lt;/P&gt;&lt;P&gt;risk-rating-range 0-100&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;filters edit TcpSynSweep &lt;/P&gt;&lt;P&gt;signature-id-range 3030&lt;/P&gt;&lt;P&gt;attacker-address-range $HTTP_Proxy&lt;/P&gt;&lt;P&gt;victim-address-range 1.1.1.1&lt;/P&gt;&lt;P&gt;actions-to-remove produce-alert&lt;/P&gt;&lt;P&gt;stop-on-match True&lt;/P&gt;&lt;P&gt;user-comment Stop on Match&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;filters move TcpSynSweep begin &lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to get the sensor completely tuned and installed. Other than updates it had only the one rule. Figured this would be a good place to start. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brent &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:31:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699847#M87189</guid>
      <dc:creator>bberry</dc:creator>
      <dc:date>2019-03-10T10:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Event Action Filters</title>
      <link>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699848#M87190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok .. see I really do need a reference. If I am understanding everything right, What I did and what is recommended are the same thing other than the recommendation is using specific victim addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that every network is different and there will probably not be a definate list but what about the type of thinks to look for when tuning a new sensor? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brent &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 15:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699848#M87190</guid>
      <dc:creator>bberry</dc:creator>
      <dc:date>2007-03-21T15:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Event Action Filters</title>
      <link>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699849#M87191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Creating Event Action Filters:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008055df7a.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008055df7a.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you added the Filter, did you click Apply and log off gracefully?  Are you using VMS with IPS Management - could a lack of syncing VMS with your sensor have caused an overwrite?  It might have deleted if your syntax was wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recommend you remove the public/private IP addresses of your proxy server from your original post - you've just identified a key component of your security infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You want stop on match checked if you don't want any more precise filters to override your first filter.  Your victim address range should be 0.0.0.0-255.255.255.255.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create your rule using the GUI - save - then go back to the CLI and copy the text version.  You can then use that as a template for future rules.  I personally prefer the GUI for something as complex as that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2007 14:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699849#M87191</guid>
      <dc:creator>RichardSW</dc:creator>
      <dc:date>2007-03-22T14:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Event Action Filters</title>
      <link>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699850#M87192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I created the original filter via the GUI but I guess was just a little impatient in waiting for it to fire. While I was waiting I went ahead and pasted the recommended filter onto the CLI and did the apply but I had to reload the sensor to get it to appear in the list. That is when I noticed that both my original and the recommended solutions were basically the same. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not using the VMS as I only have one sensor. Am I loosing somethig by not using it? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do like the GUI interface better than the CLI as it makes adding and changing things easier. Now I just need to learn and understand everything that is in the event log. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought about pulling the IP addresses but message was already permanent when I cam back to change. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2007 15:13:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-event-action-filters/m-p/699850#M87192</guid>
      <dc:creator>bberry</dc:creator>
      <dc:date>2007-03-22T15:13:38Z</dc:date>
    </item>
  </channel>
</rss>

