12-16-2003 10:22 AM - edited 02-20-2020 11:09 PM
I have a Cisco 4235 IDS sensor and I am using VMS 2.2 to monitor traffic flow. I have almost got my alarms tweaked to where I would like them and now what I would like do is email alerts to myself and others using VMS. Can someone tell me how to set this up? Thank you.
I would also like to start using the shun option on the pix based on particular events. Is there a way to set it up? Also, can you specify the amount of time that it will shun? I am pretty new at this, so please "dummy up" instructions.
Thank you
12-17-2003 09:36 AM
Please refer to the below url for configuring the blocking. By default, the shun time is 30 minutes.
http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mgt_ids/idsmc12/ug/ch05.htm#893118
The master document is
http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mgt_ids/idsmc12/ug/index.htm
12-17-2003 09:44 AM
Forgot about the email notification.
http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mon_sec/secmon12/ug/ch05.htm
In Security Monitor-->Admin-->System Configuration-->Email server configure the email server.
From the above link, configure the Event notification for alarm events and/or for the database rules for any notification that you would like for any database related events.
thanks,
yatin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide