cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
514
Views
0
Helpful
2
Replies

VMS SEC MON

jlwomeld
Level 1
Level 1

Question on VMS 2.3 in the SEC MON(sensor is a IDSM2) events I have notice that on one of my sensors the following Alert Detail: Traffic Source int0(other details show int7 as my source):, is this the TCPRESET port? if so I do not have that SIG set to do this. the SID ID=1203 GFRag Overwrite.

Thanks

2 Replies 2

ibanezm
Level 1
Level 1

what sensor version are you running? the only difference on the alert should be resetTcpFlowSent: true, the sensing interface on the idsm2 remain ge7 and ge8. I'd like to see the entire alert from the cle... show ev al

Version 4.1(5)S201

Sig Name Sensor Name Alert Details Local Date

CARL322IDSINDIA Frag Overwrite Traffic Source: int0 ; Wed, Nov 09, 2005 02:46:00 PM

here is my config for my SPAN

monitor session 10 source interface Gi1/1 - 2 rx

monitor session 10 source interface Gi2/1 rx

monitor session 10 destination intrusion-detection-module 8 data-port 1

Review Cisco Networking for a $25 gift card