Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Adaptive Security Appliance, Secure Firewall Management Center, and Security Cloud Control.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

I have recently hooked up a 4240 and found a lot of internal traffic, producing this alarm. SIG ID 5307.In looking at the packet data it seems to be ligitimate traffic - gmail and others. The NSDB lists no benign triggers. Does anyone have any other ...

Please help if you know the solution… may be I updated to 5.x too early. Had few cases then sensor starts to generate thousands of alerts for a single signature all of the sudden. False-positive alerts for sure. The only solution is to disable the si...

DSmirnov by Level 3
  • 469 Views
  • 1 replies
  • 0 Helpful votes

Greetings all. Using the CLI (or from the shell) on an IPS v 5.0 sensor, can anyone detail a quick way to generate a listing of all signatures and their corresponding information (sig-id, subsig-id, sig-name, engine name, SigStringInfo, etc…).I unde...

gdntsoc by Level 2
  • 459 Views
  • 1 replies
  • 0 Helpful votes

...wanted to pose a general question to the forum.If I configure/enable 'produce-verbose-alert' as an event action override (globally), will this cause any peformance issues with an IPS v 5.0 sensor? I understand that there are other variables such a...

gdntsoc by Level 2
  • 832 Views
  • 1 replies
  • 0 Helpful votes

I have a CISCO PIX 501 Configured and working fine….All I need is to block these things for my clientsYAHOO MessengerMSN MessengerAnd also I don’t need to give www access ( Internet Browsing ) to few of my users.But all must have access to use their...

ahmadnaveed by Community Member
  • 1177 Views
  • 6 replies
  • 0 Helpful votes

Hi all.I have an IDS configured on a PIX515e. Information messages and Alarm messages generated generated from PIX are logged in a Linux box.I appreciate any suggestion about some Linux tool that I can use to parse this log.Tks in advanceGiovanni

I have enabled Blocking on the 4240 and have set the Blocking Device as our Pix 515E. When I look at the Signature Configurations quite a few Signature Actions are set to Produce Alert only. If blocking is enabled do you have to also go and set the S...

jmacdonald by Community Member
  • 591 Views
  • 1 replies
  • 0 Helpful votes

Hopefully someone will be able to give me a hand with this issue. Basically I wanna swap my 501 with a 505 I've configured it properly (I think I did). When I plug it in the network I can ping my ISP router, but my servers on the inside cannot access...

pj_mtl by Level 2
  • 2535 Views
  • 13 replies
  • 0 Helpful votes

I'm trying to use the logging facility to refine an Access List in a test network. At the end of a list of ACE's I have a "permit ip any any log 5"I had the idea that only the flows that had fallen through all of my other rules would reach this last...

sgoldman by Community Member
  • 682 Views
  • 3 replies
  • 0 Helpful votes
Review Cisco Networking for a $25 gift card