09-22-2011 09:29 AM - edited 03-10-2019 05:29 AM
Hi,
In one of our customer “Echo Test “ signature is triggering on CISCO IPS for private to private IP and some time source and destination IP’s will be 0.0.0.0.
Can any one help me to understand what is this signature and why it’s triggering.
Thanks & Regards,
Tejesh. U
09-22-2011 11:30 AM
The 0.0.0.0 address appears in Summary Alerts. Multiple signature triggerings have been Summarized into a single Alert. Instead of listing every address from the individual triggerings the Summary alert will put 0.0.0.0 in for either the source address, destination address, or both addresses depending on the type of Summarization being done.
You can tune the signature itself to disable Summarization if you really need to see the individual addresses.
Keep in mind, however, that Summarization is used to keep the sensor from flooding your monitoring station with alerts for every triggering.
09-23-2011 01:53 AM
Dear marcabal,
Thanks for your valuable information.
Please let me know what is this "Echo Test" event and in which situation and why this kind of signature will trigger. Can we ignore this kind of events.
Can you please help me to understand.
Thanks & Regards,
Tejesh. U
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide