cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
687
Views
0
Helpful
1
Replies

IDS Signatures

joe
Level 1
Level 1

I currently have a Cisco 4235 NIDS with VMS. I am trying to research more information on the signatures that are being reported in our daily reports. Do you know where I can start researching the signatures and the possible resolutions?

Is there a best practices guide to managing IDS?

1 Reply 1

a.arndt
Level 3
Level 3

A great way to start, IMHO, is to read the NSDB entry for each SigID that you have questions about. Using a browser, you can navigate through the description provided by Cisco and further drill into and find all the supporting technical information (including links) used to develop the alarm.

If you want to check the latest threats Cisco is building a signature for, as well as the NSDB online, it is available at the following URL:

http://www.cisco.com/pcgi-bin/front.x/ipsalerts/ipsalertsHome.pl

I hope this helps,

Alex Arndt

Review Cisco Networking for a $25 gift card