07-21-2005 11:24 AM - edited 03-10-2019 01:33 AM
I can't figure how to get the "trusted networks" to stop alerting alarms.
Two signatures are CISCO IOS Interface DOS and Invalid IGMP Header DOS. which broadcast multicast 224.0.0.x all day on the wire from their VLAN interfaces.
I have tried configuring through the VMS MC, the "trusted networks" and also disabling these signatures with no luck.
VMS tells me the push is successful.
Using IDSM2 sig vers 181. Any advice?
07-27-2005 10:09 AM
Basically you need to disable those signatures for your trusted networks for it to stop alarms for those networks.
07-28-2005 09:46 AM
I've tried doing just that with no luck. The only way to stop "presenting" them, is creating a event viewer filter and plugging in the internal interfaces, subnets etc. then the signature events will stop.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide