<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic false positives with CSA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/false-positives-with-csa/m-p/386645#M99518</link>
    <description>&lt;P&gt;CSA generates Warnings along the lines of:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An unauthorized Network Component, 'NDIS Proxy' was detected registering with the system. The operation was permitted. Details Rule 424 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;An unauthorized Network Component, 'QoS Packet Scheduler' was detected registering with the system. The operation was permitted. Details Rule 424 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Typically I get 4 of these per reboot on a number of systems; these systems are healthy and need NDIS proxy and Qos Packet scheduler etc in order to work....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SO I think these are false positives and would like them NOT to generate noise....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is i dont want to turn off Rule 424 if its needed and wonder how to work around the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems no obvious way to stop the logging or exclude the applications in question; the only option is to enable/DISable the rule....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas or suggestions welcomed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;dave&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:18:53 GMT</pubDate>
    <dc:creator>dave.thornton</dc:creator>
    <dc:date>2019-03-10T09:18:53Z</dc:date>
    <item>
      <title>false positives with CSA</title>
      <link>https://community.cisco.com/t5/network-security/false-positives-with-csa/m-p/386645#M99518</link>
      <description>&lt;P&gt;CSA generates Warnings along the lines of:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An unauthorized Network Component, 'NDIS Proxy' was detected registering with the system. The operation was permitted. Details Rule 424 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;An unauthorized Network Component, 'QoS Packet Scheduler' was detected registering with the system. The operation was permitted. Details Rule 424 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Typically I get 4 of these per reboot on a number of systems; these systems are healthy and need NDIS proxy and Qos Packet scheduler etc in order to work....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SO I think these are false positives and would like them NOT to generate noise....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is i dont want to turn off Rule 424 if its needed and wonder how to work around the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems no obvious way to stop the logging or exclude the applications in question; the only option is to enable/DISable the rule....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas or suggestions welcomed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;dave&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/false-positives-with-csa/m-p/386645#M99518</guid>
      <dc:creator>dave.thornton</dc:creator>
      <dc:date>2019-03-10T09:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: false positives with CSA</title>
      <link>https://community.cisco.com/t5/network-security/false-positives-with-csa/m-p/386646#M99519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need to disable it.  Change the Sniffer and protocol detection rule to exclude those protocols.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Mar 2005 20:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/false-positives-with-csa/m-p/386646#M99519</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2005-03-07T20:27:32Z</dc:date>
    </item>
  </channel>
</rss>

