cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1454
Views
0
Helpful
2
Replies

Intrusion monitor events

peter.peng
Level 1
Level 1

Hi Sir:

   What event will trigger any session to log the Reason type of "Intrusion Monitor".

The Firepower just think the session is not really hight critical and it will not compromise our client. So it will log of Intrusion Monitor , Right ? Or it has other reason ?

Could you provide me any recommendation ?

2 Replies 2

Intrusion event are consist of many factors where the packet is malformed. 

The system examines the packets that traverse your network for malicious activity that could affect the availability, integrity, and confidentiality of a host and its data. When the system identifies a possible intrusion, it generates an intrusion event, which is a record of the date, time, the type of exploit, and contextual information about the source of the attack and its target. For packet-based events, a copy of the packet or packets that triggered the event is also recorded.

 

IPS policy is facilitated by a dedicated user interface with the following features.

1. Rule Management interface

2. layered approach to policy configuration

3. layers can be shared across policies.

 

check this link

https://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Intrusion-Events.pdf

please do not forget to rate.

That didn't actually answer the question.

What does it mean when it sys Intrusion Monitor in the Reason column within the connection events?

Review Cisco Networking for a $25 gift card