cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
895
Views
0
Helpful
3
Replies

what are the usual practices if find attacks records from Cisco IME?

martlee2
Cisco Employee
Cisco Employee

what are the usual practices if find attacks records from Cisco IME?

is it to update firmware the only action that users can take?

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

If IME is reporting events that were incoming connection attempts blocked by the IPS then no further action is required.

If an internal device is the source then additional remediation may be indicated depending on what trigger event is detected.

in victom report,high severity , no action in excel file, whats should do?

Cisco IOS NX-OS Malformed LISP Packet Denial of Service 7170/0
DNS Query Name Loop DoS 6065/0

The first one is tellilng you that the detected IOS or NX-OS version on one or more of your devices has this vulnerability. LISP is seldom seen in small or medium enterprise and if you do not have it configured, it's not an issue.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuu64279/?referring_site=bugquickviewredir

The second one generally points to DNS misconfiguration somewhere in your network. You'd have to look more closely at the victim system to determine more information and whether or not it is important in your environment.

In general, IPS alerts are a starting point for security operations to perform investigations. You're using the older discontined IPS type and it does not have the flexibility of self-tuning like the newer FirePOWER-based systems do.

Review Cisco Networking for a $25 gift card