11-09-2005 08:36 AM - edited 03-10-2019 01:44 AM
Question on VMS 2.3 in the SEC MON(sensor is a IDSM2) events I have notice that on one of my sensors the following Alert Detail: Traffic Source int0(other details show int7 as my source):, is this the TCPRESET port? if so I do not have that SIG set to do this. the SID ID=1203 GFRag Overwrite.
Thanks
11-09-2005 02:58 PM
what sensor version are you running? the only difference on the alert should be resetTcpFlowSent: true, the sensing interface on the idsm2 remain ge7 and ge8. I'd like to see the entire alert from the cle... show ev al
11-10-2005 07:24 AM
Version 4.1(5)S201
Sig Name Sensor Name Alert Details Local Date
CARL322IDSINDIA Frag Overwrite Traffic Source: int0 ; Wed, Nov 09, 2005 02:46:00 PM
here is my config for my SPAN
monitor session 10 source interface Gi1/1 - 2 rx
monitor session 10 source interface Gi2/1 rx
monitor session 10 destination intrusion-detection-module 8 data-port 1
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide