01-21-2003 12:18 AM - edited 03-09-2019 01:45 AM
Hello,everyone!I have a 6509's ids module and ids-mc(included vms2.1).
I need to use ids-mc to manage and mointor ids module,but when I setup
a group of signiatures and deploy them to ids module.IT seems like the
policy take any effect.
Do you tell me how can I judge the ids moudule's status.Why the
ids module don't work?
Thanks!!!
01-21-2003 11:00 AM
Are you trying to filter out(exclude) events(ie. source,destination with certain signatures)? I am having issues with IDS-MC filtering(exclude) information on an IDSM blade. I think the only method that works is a host to host filter setup. Any other filter setup such as host to any or any to any filter does not work. I have a case open with the TAC currently on my issue.
01-22-2003 06:04 AM
Well it looks like the host to host exclusion method for signature does not work either.
03-26-2003 11:15 AM
I am seeing the same. I have not yet tried host to host, but this would be a very impractical solution for my problem as I am trying to filter entire networks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide