05-29-2008 05:37 AM - edited 03-10-2019 04:07 AM
New to Cisco IPS....
I wish to EXCLUDE a single destination IP address from a signature -- have the sig fire it it trips for all BUT one IP address (which is a confirmed false positive).
The sig name is BO2K-UDP. want to have it ignore events for a single destination but have it trip normally for all other destinations. Thanks.
05-29-2008 08:11 AM
You want to set up an Event Action Filter.
Here's the 6.0 version:
http://www.cisco.com/en/US/docs/security/ips/6.0/configuration/guide/cli/cliEvAct.html
05-29-2008 09:03 AM
thank you for for your quick reply... must this be done via CLI or can it be done in the GUI? Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide