08-04-2021 10:35 PM
Hi Team,
Hope you all are doing good.
please help me in below.
let take a example that we have Cisco IPS connected outside interface with Internet router and Inside conneted with Server.
As a testing i will attack on the server from outside and i want IPS to detect these attack not to block so for that do i have to configure access control rule with action Trust or do i have to create some other rules ?
my requirement is very simple i want IPS to detect all those attacks originated from source X to destination Y, I dont want these attacks to be blocked by IPS
please suggest.
Solved! Go to Solution.
08-05-2021 07:53 PM
Do not use a trust rule - that will bypass the IPS rules for the configured flow.
Instead use an allow rule for the source of the simulated attack with a custom IPS policy whose rules are all set to detect (and not block/drop).
08-05-2021 07:53 PM
Do not use a trust rule - that will bypass the IPS rules for the configured flow.
Instead use an allow rule for the source of the simulated attack with a custom IPS policy whose rules are all set to detect (and not block/drop).
08-06-2021 09:01 PM
Hi Marvin,
Thanks for your response.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide