07-30-2003 11:15 PM - edited 03-09-2019 04:16 AM
Hi all ,
I have a problem here , I need to ignore a specific signature from specific network , I know how to do this , but I need to ignore it if coming from specific source port . Does anybody know to do this ?
Thanks for your help
07-30-2003 11:18 PM
Sorry , I forgot to mention I have Cisco IDS 4230 version 3.1(3)S49 .
07-31-2003 08:20 AM
x
08-03-2003 02:43 AM
Hi all,
does anybody have solution to this ? or this can't be done on cisco IDS ?
Thanks
08-03-2003 04:29 PM
Hi.
F.Y.I.
In packetd.conf, there's a section "# Excluded events" which
I think you can specify if you take that sig or not depending on
Source IP address/Network and Destination IP address/Network.
RecordOfExcludedAddress SigID SubSigID SrcIP/Network
RecordOfExcludedPattern SigID SubSigID SrcIP/Network DstIP/Network
And when you look into the Cisco online manual
There you can find "Included" also. such as below.
RecordOfIncludedAddress SigID SubSigID SrcIP
RecordOfIncludedPattern SigID SubSigID SrcIP DstIP
Appologize if you've already had this info.
Best Regards,
Kentanu
--
10-29-2003 03:03 PM
I have asked this same question. The answers I have received were that it cannot be done. I am running version 4.1. I was told by Cisco that this should be pushed through our sales team to get it implemented in future releases.
10-30-2003 10:17 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide