cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
542
Views
0
Helpful
1
Replies
Highlighted
Beginner

source port 0 with Summarize set to 15

See Sig. ID 5930/0 in IME in Event Monitoring as an example.

If the Alert Frequency, Summary mode of an IPS signature is set to Summarize with a value of 15, does this mean that all 15 hits receive the stated Action Taken (eg. dropped packet, deniedFlow, tcpOneWayResetSent) as in the first alert triggered.

Is it true that the display of 'port 0' in the next triggered event represents the following 14 events which also experience the same action taken as the first, but the Actions Taken words (dropped packet, deniedFlow, tcpOneWayResetSent) are not displayed (ie. the field is blank).

Can someone clear this up for me?

Thanks.

WG

Everyone's tags (2)
1 REPLY 1
Cisco Employee

source port 0 with Summarize set to 15

Hi,

Yes, actually what will happen is that after X amount of events (times triggered the signature) on an X amount of time you will see an event generated.

The action will be the same for all events (times triggered the signature) but message will only display after X amount of events

http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/clisgdef.html#wp1040171

HTH

Luis Silva

"If you need PDI (Planning, Design, Implement) assistance feel free to reach us"

http://www.cisco.com/web/partners/tools/pdihd.html

Luis Silva
CreatePlease to create content
Content for Community-Ad
FusionCharts will render here