<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSA (Host IDS) and Source IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522530#M98611</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can the other rules be modified into NACL rules?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Apr 2006 13:55:44 GMT</pubDate>
    <dc:creator>RichardSW</dc:creator>
    <dc:date>2006-04-07T13:55:44Z</dc:date>
    <item>
      <title>CSA (Host IDS) and Source IP</title>
      <link>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522527#M98608</link>
      <description>&lt;P&gt;I am monitoring CSA Agents on the CiscoWorks Security Monitor.  I notice that most alerts, specifically the alerts triggered by web server exploit attempts, don't record the Source IP address and Port of the attacker.  I understand the difference between NIDS and HIDS, but having past experience with Sygate, I don't understand why the CSA Agents aren't capable of also recording this additional network information to help with alert analysis?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could I have something configured improperly?  Or is Cisco's HIDS just that specific?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522527#M98608</guid>
      <dc:creator>RichardSW</dc:creator>
      <dc:date>2019-03-10T09:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: CSA (Host IDS) and Source IP</title>
      <link>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522528#M98609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have any experience using the CiscoWorks Security Monitor but CSA hosts reporting to the CSAMC on VMS report source IP and port information.  It is based on rules whether it allows, denies and logs the information.  Does the CiscoWorks Security Monitor allow you to modify the rules that apply to the CSA hosts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Apr 2006 18:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522528#M98609</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2006-04-06T18:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: CSA (Host IDS) and Source IP</title>
      <link>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522529#M98610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only Network Access Control List (NACL) rules show IP information in the logs.  The other rules log different stuff.  It cannot be turned on either.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Apr 2006 20:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522529#M98610</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2006-04-06T20:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: CSA (Host IDS) and Source IP</title>
      <link>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522530#M98611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can the other rules be modified into NACL rules?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2006 13:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-host-ids-and-source-ip/m-p/522530#M98611</guid>
      <dc:creator>RichardSW</dc:creator>
      <dc:date>2006-04-07T13:55:44Z</dc:date>
    </item>
  </channel>
</rss>

