cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
780
Views
0
Helpful
6
Replies

Alerts

prashantrecon
Level 1
Level 1

Hi All,

I have tunned signatures for u torrent to get alerts on ips.

Used utorrent on pc  to download software but still i am not receving any events on ips.

What may be the issue.Ping and traceroute works fine from pc to ips.

Can anyone guide to tune basic signature to get alerts on ips?

6 Replies 6

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Prashant,

Do you get events with ICMP traffic?

Regards

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hi ,

By default in IPS icmp echo reply and echo request signature is disable.

i getting only events related to global correlation.(curreltly i am not using global correlation , i have not configured it)

Regards,

Prashant

Hello Prashant,

By default in IPS icmp echo reply and echo request signature is disable.

Exactly so why dont you enable it and set it to generate an alert so you can see them??

I mean I dont think I understand your question is this is not what you are looking for!!!

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Actually my issue is that for example if i enable the Echo reply and echo request signature and when i ping to any website or ip i am not getting any alert on my ips.

and also if i am looking for last 72 hours events in cisco ASDM for ips i am not getting any events except ""

A global correlation update failed: openConnection: ""

About 15 days before i am able to see last 24 hours events(example dos attacks)

any clue why there is no events generating in IPS.

Regards,

Prashant

Can you share the running configuration for that particular signature, or take some captures related to the signature configuration and post it here.

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hi,

let take a example echo reply and echo request .

Can you help me to take capture and running cofig for above mention signature.

Reagrds,

Prashant

Review Cisco Networking for a $25 gift card