05-06-2014 06:36 AM - edited 03-10-2019 06:11 AM
Hi!
I want to tune IPS module (SSP) in ASA-5545-X for work with the signature 6920/0 (Net flood TCP), 6910/0 (Net Flood UDP) and 6901 (Net Flood ICMP ..).
My settings:
signatures 6901 0
status
enabled true
retired false
exit
exit
signatures 6902 0
status
enabled true
retired false
exit
exit
signatures 6903 0
status
enabled true
retired false
exit
exit
signatures 6910 0
status
enabled true
retired false
exit
exit
signatures 6920 0
engine flood-net
event-action produce-alert|produce-verbose-alert
exit
status
enabled true
retired false
exit
The parameter "rate" in signatures is default, but I don't see an alert. The alert must be sent every 30 second with "Rate" = 0.
Thanks!
05-06-2014 06:42 AM
P.S. I use promiscuous mode and I sure my IPS to work, because a other signature are work correctly.
05-07-2014 03:12 AM
I had rebooted the module and signatures worked.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide