cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
859
Views
0
Helpful
5
Replies

configure an excepcion for a host in an IPS4260

Luis Carranza
Level 1
Level 1

Hi guys!!

I need your help to know if it's possible to configure an excepcion for a specific host or ip address in an IPS 4260, I can do this in an AIP-SSM configuring an access-list, but I think it's different on an appliance.

Regards

1 Accepted Solution

Accepted Solutions

raga.fusionet
Level 4
Level 4

Hi Luis,

An exception on IPS is called an event action filter, I was looking for a config example but instead I found this nice youtube video:

http://www.youtube.com/watch?v=Ho945eUSwbo

If you have a host that is firing a lot of false positives just select it as "attacker" and leave the signature range blank if you dont want to see any signature at all coming from this guy.

I hope this helps.

Raga

View solution in original post

5 Replies 5

raga.fusionet
Level 4
Level 4

Hi Luis,

An exception on IPS is called an event action filter, I was looking for a config example but instead I found this nice youtube video:

http://www.youtube.com/watch?v=Ho945eUSwbo

If you have a host that is firing a lot of false positives just select it as "attacker" and leave the signature range blank if you dont want to see any signature at all coming from this guy.

I hope this helps.

Raga

Thinking about it, I dont think blank works. You can enter a single signature ID, a  comma-separated list, or a range of IDs. The default is to apply the  rule to signatures in the range 900-65535.

Luis is correct, you want to configure an Event Action Filter for your host IP.

Here's the documentation page for 7.0 CLI:

http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_event_action_rules.html#wp1030749

- Bob

Thanks Luis

This was really helpful!!!

Thanks

Awesome, Glad I could help

Have a good one!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: