cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
527
Views
0
Helpful
3
Replies

IOS 12.3 IP/FW/IDS Logging question

slade
Level 1
Level 1

Hello, I have a little 26xx running 12.3 with IP/FW/IDS. I am logging to a syslog server. The problem is, I get a large amount of ICMP sig log entries (especially #2004 ICMP Echo Request). I want to continue using the IOS IDS module on the router to handle all the sigs it is now, just I want to selectively choose which ones I am notified of. For example, I would like to disable notification for sig 2004 but not disable the sig globally. Any advice is appreciated.

3 Replies 3

umedryk
Level 5
Level 5

Either you can remove the IDS response as log or you can selectively choose which messages can turn up at syslog server.

Great, how do you selectively choose what messages are logged to the syslog server?

you can disable signatre 2004 by the config cmd:

ip ips sig 2004 disable

You can also configure this signature to send logs only for selective traffic using the cmd:

ip ips sig 2004 list

Review Cisco Networking for a $25 gift card