03-27-2003 11:10 PM - edited 03-09-2019 02:40 AM
Our IDS shun some regular web pages due the signature no 5351. Is this normal? Is there any risks to allow traffic containing this signature code?
04-02-2003 01:26 PM
If indeed regular web pages are being wrongly shunned, you could fine tune your setup to exclude signature/s wrt a specific host or network address. The process is described at http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a008009404e.shtml. However, you need to be careful while doing this. Purging could cause False negitives or the faliure to detect actual malicious activity. Another thing, I don't think that signature 5351 is supported by Cisco IOS. This is as per the 'Cisco IOS Intrusion Detection Systems Signature List' at http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_data_sheet09186a008014c532.html.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
Log in to Community