Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Is there any way to receive a notification (SNMP trap to Orion would be perfect), or collect some kind of report that tells the date/time a phone (specifically desktop IP phones, 7945/7965s) are unregistered/registered. We'd like to more proactively...
On the IDS behind the firewall, I would like to create a filter to exclude all signatures that have a source address from my server's subnet (filter all supposed attacks coming from my servers). My questions is whether the IDS still capture alarms a...
We have a resident student network, which coexists with the rest of the campus network. I want to keep the students behind the firewall (less likely that machines get comprimised) but I also want to keep them isolated from the rest of the internal f...
I have a couple questions:1. If I go into IDM | Configuration | Sensing Engine | Filtered Signatures, and I want to filter out a whole class C network of destination IP addresses, should I just make an entry like: 192.168.1.0 for the whole network, o...
I have 2 sensors in place, one sensor sees a mirror of the inside interface of the PIX and the other one uses a mirror of the uplink ports to the servers Cat6500 switch. All my servers are in one class C address range.In IEV, I get 2 alarms for ever...
Per TAC: As you may be aware, Linux often has multiple ways to configure various functions. Products the Wireless Networking Business Unit makes that have a Linux operating system are designed to look at /etc/localtime for their timezone offsets, no...
Thanks Luis - that error is exactly what I need to catch. I cannot seem to find where in RTMT I can get it to trigger an alert based on that error message. Do you know? Thanks again
Yes, its cumulative.I noticed the same thing with the file size. I was running S35. I downloaded and installed the S39. While doing that, I checked the readme files for S37 and S38 for what new signatures were included. After the upgrade from S35...
Mirror the port that comes from the inside or outside interface of the firewall. Then take a laptop, put it on the mirrored port, load the sniffing program of your choice, create a capture filter with this systems IP address, and let it begin collec...