<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vms  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vms/m-p/352259#M97212</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes nataraj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this filter will eliminate the events generated on the security monitor, with the specified source/destination/signature id etc... its only on the security monitor, that you are filtering events.. hope you got it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Feb 2005 05:18:19 GMT</pubDate>
    <dc:creator>sachinraja</dc:creator>
    <dc:date>2005-02-03T05:18:19Z</dc:date>
    <item>
      <title>vms</title>
      <link>https://community.cisco.com/t5/network-security/vms/m-p/352254#M97198</link>
      <description>&lt;P&gt;Dear All ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;iam getting lot of alerts on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9017 - Back Door Probe (TCP 5401) . i found in my &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vms server ( D:\Program Files\CSCOpx\CSAMC\cfg ) ssl-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bundle file [BUNDLE_CONF]&lt;/P&gt;&lt;P&gt;mc.server_cert_cn=itvms&lt;/P&gt;&lt;P&gt;mc.http_port=80&lt;/P&gt;&lt;P&gt;mc.https_port=5401&lt;/P&gt;&lt;P&gt;mc.alt_https_port=443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is tht all alerts are coming due to this vms server listening on 5401 port ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls reply ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Nataraj&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms/m-p/352254#M97198</guid>
      <dc:creator>nataraj_v</dc:creator>
      <dc:date>2019-03-10T09:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: vms</title>
      <link>https://community.cisco.com/t5/network-security/vms/m-p/352255#M97199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The default port for CSA agent to MC communication is 5401, with a fallback to 443 if that fails.  So yes, this traffic will also set off IDS signature 9017 since all it is looking for is a TCP SYN on port 5401.  The benign triggers for this event listed in the NSDB do state:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;Benign Trigger(s):  It is entirely possible that a machine is running a service on the same port as a known trojan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Signature Filter:  Exclude systems running a valid service on the port in question as destinations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My recommendation would be to add a filter for this signature with a destination address of your VMS server, that will eliminate all these signatures firing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Feb 2005 03:17:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms/m-p/352255#M97199</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2005-02-01T03:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: vms</title>
      <link>https://community.cisco.com/t5/network-security/vms/m-p/352256#M97201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sir ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very much gfullage, but i never done adding this filter to a sig. could u pls guide me. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my setup i m using cisco nids 4235 sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and we have 2 sensors in eachlocation. 1 is for incoming traffic and other outgoing traffic.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;our wan is centralized and all nids ( in each location 2  nids ) will send alerts to our VMS server. now in which sensors should i add this filter so tht i wont get alerts on 9017 .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards.&lt;/P&gt;&lt;P&gt;Nataraj&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2005 05:02:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms/m-p/352256#M97201</guid>
      <dc:creator>nataraj_v</dc:creator>
      <dc:date>2005-02-02T05:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: vms</title>
      <link>https://community.cisco.com/t5/network-security/vms/m-p/352257#M97204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi nataraj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to add it on the server, where you get these alerts. When you filter any signature on the VMS, it is applied onto to the IDS automatically, and the signature can no longer be seen on the security monitor. if this is a false poisitive, you can configure a filter as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) on the IDS MC, click configuration&amp;gt;settings. &lt;/P&gt;&lt;P&gt;2) If you have only one IDS, u you will find a tab TOC with a lot of options like identification, settings, filters etc...&lt;/P&gt;&lt;P&gt;3) on the filter menu, give the signature,source addr &amp;amp; dest addresses as desired by you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can find information about this on the following URL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/cscowork/ps3990/products_user_guide_chapter09186a008031b030.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/cscowork/ps3990/products_user_guide_chapter09186a008031b030.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this helps.. all the best..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2005 05:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms/m-p/352257#M97204</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2005-02-02T05:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: vms</title>
      <link>https://community.cisco.com/t5/network-security/vms/m-p/352258#M97208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear SachinRaja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank u very much , I did so ,i created a exclusive filter on 9017 for present alerts.source is (My VMS Server ) and destination is internal lan . pls confirm me , the signature will eliminate alerts on from the above source and destination but alerts on other source and destination. is it rt ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;Nataraj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2005 03:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms/m-p/352258#M97208</guid>
      <dc:creator>nataraj_v</dc:creator>
      <dc:date>2005-02-03T03:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: vms</title>
      <link>https://community.cisco.com/t5/network-security/vms/m-p/352259#M97212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes nataraj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this filter will eliminate the events generated on the security monitor, with the specified source/destination/signature id etc... its only on the security monitor, that you are filtering events.. hope you got it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2005 05:18:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms/m-p/352259#M97212</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2005-02-03T05:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: vms</title>
      <link>https://community.cisco.com/t5/network-security/vms/m-p/352260#M97215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im still getting alerts from this source (10.0.67.120 ) to destination (10.1.1.34) ( This is  gateway ip ,where nids sensor is present ) . as u know i applied exclude filter from the above soruce and destination.  y im still getting alerts even though i applied filter on vms . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;Nataraj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2005 09:12:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms/m-p/352260#M97215</guid>
      <dc:creator>nataraj_v</dc:creator>
      <dc:date>2005-02-04T09:12:40Z</dc:date>
    </item>
  </channel>
</rss>

