Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I am curious as to the IDS differences between the IDS features in PIX, Switches, Routers as compared to the well known feature set of the 42xx appliance.I was once under the impression that the PIX and Router/Switch IDS implementations were a subset...
Come on Cisco, please tell us the details of this signature.I would be naive to say that all 'bleeding edge' signatures are accurate as opposed to cosmetic. Everyone races to provide signatures for the latest and greatest threats, but the details of ...
Don't know where to make feature requests, but here it is:When setting a signature to IPLog when triggered, the IPlog show up in the IDM Screen under Monitoring->IP Logs.They include a Log ID and an IP address.There is also a hover function over the ...
Have been seeing this signature recently (for the first time ever mindst you).According to the description it occurs whenever the protocol field is greater than 133.VMS reports the source Ip as 0.194.132.65, like that.Also getting various No INitial ...
Couple of issues here:After enabling this new signature, I started receiving false positives right away. Does this not occur within your own testing environment?I can provide traffic dumps if you like, I've done it before. Should I just accept this a...
Same, v4.1-4-S94Also my target is an Oracle server running under Solaris 2.8, not Compaq unfortunately.We use AD within our corp. but these packets have only been seen at the dmz point.Nice to see Cisco looking in to it.
Looks like it all it does is check the Host field of the site being connected to(from the signature itself)Host[:][ \t]+photo[.]exectech[-]va[.]comis the regex it checks in the Header.Never seen it myself, but it would certainly warrant a sniff.Sound...
I concur. Have been seeing this traffic on my DMZ sensors for a couple of weeks now. I do not see it internally.Here's the captured packet from the No initial frag (the incomplete dgram is just more 0x3f stuff)Frame 1 (70 on wire, 70 captured) Arr...