cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
377
Views
5
Helpful
3
Replies

How to add a filter to signiture?

cbergel
Level 1
Level 1

A specific host allways attack to our network.This host is using DNS Server.We don't want this to be detected as an attack.How to add a filter to this signiture?

signiture id 4003 "Nmap UDP Port Sweep"

3 Replies 3

shawn.posthumus
Level 1
Level 1

Heres one way:

log into your sensor via ssh

sensor#conf t

sensor#service alarm-channel-configuration virtualAlarm

sensor#tune-alarm-channel

sensor#EventFilter

sensor#Filters DestAddrs Exception False SIGID 4003 SourceAddrs SubSig *

sensor#exit

sensor#exit

save changes when prompted.

thank you very much.

garyprice
Level 1
Level 1

are you using a network IDS sensor. Like a Cisco-K9-4235? If so I can detail the very simple process to filter "out" the source from detection from the signature 4003