cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1711
Views
5
Helpful
1
Replies

SourceFire false positives because of known vulnerability scanner

brian.mcgraw
Level 1
Level 1

Hello, 

 

Our FMC is gerating/dropping a bunch of events when we perform vulnerability scans on our environment. What is the best practice to remove this noise from the FMC?  I do not need the IPS to generate alerts or drop these events. 

1 Reply 1

mikael.lahtela
Level 4
Level 4

Hi,

 

You can try prefilter or trust the scanner address, without logging.

 

br, Micke

Review Cisco Networking for a $25 gift card