01-09-2007 03:10 AM - edited 03-10-2019 03:24 AM
I am working with CISCO ASA 5540 with AIP Module, and i see a lot of events from signature 50000 "Outbreak Prevention Signature" with high severity.
Could anyone explain this signature? What does it mean? Is it useful to be enable or not?
Regards,
Cristina
01-09-2007 04:48 AM
Check following signature description
http://tools.cisco.com/MySDN/Intelligence/viewSignature.x?signatureId=50000&signatureSubId=0
This signature supports the Cisco Incident Control System (ICS) service.It you are not running Cisco ICS, this signature can safely be ignored.
M.
Hope that helps rate if it does
01-09-2007 06:49 AM
That signature should be off by default. The only time it would be turned on would be during an outbreak. It would only remain on until a more specific signature could be deployed. At that point it would be turned back off.
What version are you running ?
01-09-2007 08:36 AM
IPS 5.1(4) S260
01-09-2007 11:51 AM
Leave that signature/subsignatures Disabled.
By default they will trigger on all icmp,tcp, and udp packets.
Cisco ICS will first configure the signature to match only specific types of traffic and then Enable the signature.
Without Cisco ICS that signature is just Noise. It requires that special tuning by Cisco ICS.
So Disable that signature and just Ignore any old alerts from it if you do do not have Cisco ICS.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide