04-09-2012 03:19 AM - edited 03-10-2019 05:39 AM
Could anyone let me know what is the use / impact of adding one host IP in IDSM under - configuration- trusted host? I am trying to add a host IP which is generating legitmate traffic(to exculde this IP from reporting), however, I would like to get more information that what exatctly will happen if I add this
Thank you,
Sankar
04-09-2012 03:25 AM
Also, It says the below error when adding, please help on this
04-09-2012 03:29 AM
Well, IPS tries to connect on port 443 by defaut on the target IP address. If it is closed, you'll receive this error.
Alternatively, you can specify the port number in the command.
Regards,
Sawan Gupta
04-09-2012 03:30 AM
This isnt the IPS device, its IDSM. also , I am trying to add a trusted host.
04-09-2012 03:34 AM
Right. The trusted-host should have port 443 open.
Once a trusted-host is added, then for future communication the stored key would be used.
Please have a look at the following link:
http://www.cisco.com/en/US/docs/security/ips/6.0/configuration/guide/cli/cliTasks.html#wp1056053
Regards,
Sawan Gupta
04-09-2012 04:23 AM
Can you please explain me about my initial query
04-09-2012 04:58 AM
Adding a host as trusted-host does not mean that the traffic from that host won't be analyzed.
If you trust the traffic from a source IP, do you see any false alerts being generated ?
04-09-2012 05:56 AM
the traffic is not a false positive. I want to add the source/destination to the exclusion list so that I should not get this alrert from next time.My requirement it tell the IDSM to trust the traffic and do not declare it as malacious
04-09-2012 11:51 PM
Could you please tell us more about the network topology.
Regards,
Sawan Gupta
04-10-2012 11:45 PM
The network topology is very simple, we have server forms connected via an IDSM which is acting as NIDS. it is detecting the malacious traffic on singnature based. I got a alert that one of the server is receving the SQL injection attack from an internet IP and I checked with the server owner and he confirmed that the traffic from the internet IP is legitimate. so I want to exclude this IP from the NIDS so that I will not get this alert from next time.
04-11-2012 01:11 PM
Hi,
This case please disable the signature which is givinge alert.or tune the signature for ur server.
Regards
Rajeswar
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide