<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423825#M95102</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My software version is 4.x on an ISD 4235. &lt;/P&gt;&lt;P&gt;How can I update to 5.x version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding IEV is all ok! In my previus post i would like to intend "not running", instead of "not working"..i'm sorry. Is it normal to have traffic even if IEV isn't running and my PC not connected to IDS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francesco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Nov 2005 09:21:06 GMT</pubDate>
    <dc:creator>tasksrl7808</dc:creator>
    <dc:date>2005-11-15T09:21:06Z</dc:date>
    <item>
      <title>IDS traffic</title>
      <link>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423819#M95096</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;In one hour IDS generates 95 MB of HTTPS traffic to my IP!! (I have Cisco Event Viewer installed). Is it normal even if Event Viewer isn't working? What is the reason?&lt;/P&gt;&lt;P&gt;I have another question: is there the possibility of excluding an IP address (a target address) from the RESET, even if the rule is matched?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Francesco&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423819#M95096</guid>
      <dc:creator>tasksrl7808</dc:creator>
      <dc:date>2019-03-10T09:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: IDS traffic</title>
      <link>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423820#M95097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't really say for sure if 95MB is reasonable for your situation. It would depend on how many signatures you have enabled and alarming and they type of alarms you have generated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the second part, look for "Never Shun" settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2005 15:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423820#M95097</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2005-11-14T15:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: IDS traffic</title>
      <link>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423821#M95098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you mean the "Never Block Adresses"?&lt;/P&gt;&lt;P&gt;I have tried this setting but it's only to exclude an IP from the shun connection or shun host action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francesco &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2005 17:00:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423821#M95098</guid>
      <dc:creator>tasksrl7808</dc:creator>
      <dc:date>2005-11-14T17:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: IDS traffic</title>
      <link>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423822#M95099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Indeed, I was thinking Never Block...and you're right, that won't do what you want.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2005 19:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423822#M95099</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2005-11-14T19:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: IDS traffic</title>
      <link>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423823#M95100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As for removing the RESET.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The answer is somewhat dependant on software version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In version 4.x sensors the filtering system would only allow filtering of all actions.  This included generation of TCP Resets and producing the actual alert.  So in 4.x you coudl filter the event, but it would prevent the alert creation as well as the tcp resets (as well as any other action configured).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In version 5.x sensors the filtering system is more advanced and does allow the filtering of separate actions on an event.  So a filter can created to remove just the TCP Reset action and still leave the produce alert action.  So the alert will still be generated, without sending the tcp resets to shut down the connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2005 22:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423823#M95100</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2005-11-14T22:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: IDS traffic</title>
      <link>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423824#M95101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the sensor version? As regarding to IEV not working, were you not getting any alerts in Cisco IDS Event Viewer? In CLI, did you see alerts coming when you do "show events"? If so, make sure the sensor has been added into IEV's device list. Also IEV host can connect to the sensor successfully. You can verify the connetion by double clicking that sensor device name in IEV and see if IDM can be successfully launched in the browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2005 04:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423824#M95101</guid>
      <dc:creator>jlin1</dc:creator>
      <dc:date>2005-11-15T04:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: IDS traffic</title>
      <link>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423825#M95102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My software version is 4.x on an ISD 4235. &lt;/P&gt;&lt;P&gt;How can I update to 5.x version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding IEV is all ok! In my previus post i would like to intend "not running", instead of "not working"..i'm sorry. Is it normal to have traffic even if IEV isn't running and my PC not connected to IDS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francesco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2005 09:21:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-traffic/m-p/423825#M95102</guid>
      <dc:creator>tasksrl7808</dc:creator>
      <dc:date>2005-11-15T09:21:06Z</dc:date>
    </item>
  </channel>
</rss>

