cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
611
Views
0
Helpful
0
Replies

Add an exception IP by rule

johan.lecerf
Beginner
Beginner

Hi,

I would like to know if SourceFire has a way to add exceptions to rules for particular source/destination IP addresses.

For exemple :

This rule "OS-OTHER Bash CGI environment variable injection attempt" drops an important number of packets for this ip 10.0.0.1/32 ==> Only generates false positive events just for this IP

For this particular rule, I would like to add an IP exception to stop drop&generate event

Thanks in advance,

Best regards,

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers