<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSA: Event whose source address is 0.0.0.0 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655737#M87913</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the Ciscoworks VMS IDS MC, click configuration-&amp;gt;settings-&amp;gt;sensor or group-&amp;gt;5.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Find your signature by id, select it, click tune, check override, scroll down to alert frequency-&amp;gt;summary mode.  If it is already set to summarize, change the summary key to 'attacker &amp;amp; victim addresses' for AxBx.  This will avoid getting a 0.0.0.0 address for source or destination.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Jan 2007 15:07:06 GMT</pubDate>
    <dc:creator>attmidsteam</dc:creator>
    <dc:date>2007-01-10T15:07:06Z</dc:date>
    <item>
      <title>CSA: Event whose source address is 0.0.0.0</title>
      <link>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655734#M87908</link>
      <description>&lt;P&gt;Has anyone an event whose source is 0.0.0.0 generated by an CSA 5.1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank in advance and Merry Christmas, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cristina&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655734#M87908</guid>
      <dc:creator>lcuchisanmillan</dc:creator>
      <dc:date>2019-03-10T10:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: Event whose source address is 0.0.0.0</title>
      <link>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655735#M87910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a repeated event that has the summary key set. You can modify this by altering how that signature summarizes (i.e. source and destination and source port and destination port)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps and Happy New Year &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Dec 2006 18:29:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655735#M87910</guid>
      <dc:creator>attmidsteam</dc:creator>
      <dc:date>2006-12-30T18:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: Event whose source address is 0.0.0.0</title>
      <link>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655736#M87912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you be more precise? Could you explain me how to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cristina&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2007 09:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655736#M87912</guid>
      <dc:creator>lcuchisanmillan</dc:creator>
      <dc:date>2007-01-08T09:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: Event whose source address is 0.0.0.0</title>
      <link>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655737#M87913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the Ciscoworks VMS IDS MC, click configuration-&amp;gt;settings-&amp;gt;sensor or group-&amp;gt;5.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Find your signature by id, select it, click tune, check override, scroll down to alert frequency-&amp;gt;summary mode.  If it is already set to summarize, change the summary key to 'attacker &amp;amp; victim addresses' for AxBx.  This will avoid getting a 0.0.0.0 address for source or destination.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jan 2007 15:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655737#M87913</guid>
      <dc:creator>attmidsteam</dc:creator>
      <dc:date>2007-01-10T15:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: Event whose source address is 0.0.0.0</title>
      <link>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655738#M87914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am working with CSA 5.1 no IDS 5.1(4)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 09:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655738#M87914</guid>
      <dc:creator>lcuchisanmillan</dc:creator>
      <dc:date>2007-01-23T09:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: Event whose source address is 0.0.0.0</title>
      <link>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655739#M87915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the event and port?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The machine may be trying to connect to itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would look at other alerts on the machine(s) getting this message and see what else might be happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 18:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-event-whose-source-address-is-0-0-0-0/m-p/655739#M87915</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-01-23T18:44:53Z</dc:date>
    </item>
  </channel>
</rss>

