Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
We use an ASA 5510 as our firewall with a IDS security module. Upon running reports this morning I came across this and I am baffled.Please see attached document.What I want to know is why is it picking up an IP addy of 0.0.0.0 that's hitting our out...
We are running a 5510 router, ASA-SSM-10 sensor ver. 6.1(1)E3 w/ sig version of 368....I was wondering if there is a way to both log mac ID's if certain signatures fire? Also when we have a client VPN into our network can we grant access by mac ID in...
We've just received these new appliances and I've been trying to make heads or tails of messages received about "attacks". This is the message that I'm getting Windows DCOM Overflow 5588/0 192.168.3.34 192.168.1.7 droppedPacket, deniedFlow, tcpOneWay...
Oh cool thanks! I monitor the inside of our network that's where most of the reports come from. Occasionally I will get something from the outside trying to get in. Here's the weird thing though. I don't get any ICMP sigs firing from an outside IP ...