cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
545
Views
0
Helpful
2
Replies

Signature Fields Details

Bethuelle
Level 1
Level 1

ipsA.jpg

Can someone please give me the meaning and use of the fields found under ENGINE. To be more precise, I'll like to know how to use the fields Src Addr Filter and Dst Addr Filter.

Thanks for your answers.

1 Accepted Solution

Accepted Solutions

Dustin Ralich
Cisco Employee
Cisco Employee
Can someone please give me the meaning and use of the fields found under ENGINE.

http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_signature_engines.html#wpmkr1183504

To be more precise, I'll like to know how to use the fields Src Addr Filter and Dst Addr Filter.

Detailed by the document in the URL I provided above. In short: EAFs (Event Action Filters) based on Attacker (source) and Victim (destination) IP addresses do not always function as expected for Sweep Engine signatures. To filter Sweep Engine signatures (based on source and/or destination IP addresses), you can use the Src Addr Filter and Dst Addr Filter parameters for the signature(s) itself.

View solution in original post

2 Replies 2

Dustin Ralich
Cisco Employee
Cisco Employee
Can someone please give me the meaning and use of the fields found under ENGINE.

http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_signature_engines.html#wpmkr1183504

To be more precise, I'll like to know how to use the fields Src Addr Filter and Dst Addr Filter.

Detailed by the document in the URL I provided above. In short: EAFs (Event Action Filters) based on Attacker (source) and Victim (destination) IP addresses do not always function as expected for Sweep Engine signatures. To filter Sweep Engine signatures (based on source and/or destination IP addresses), you can use the Src Addr Filter and Dst Addr Filter parameters for the signature(s) itself.

Thanks

Review Cisco Networking products for a $25 gift card