Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
We have a 4215 IDS in place that is identifying quite a few triggers based on Cisco signatures. It does not perform any automatic countermeasures. Right now, it is just providing information. Typically it is the same 5-10 different alerts being re...
I am getting Alerts related to this Sig ID (3115). This is a Microsoft shop with an Exchange 2003 email server. Is there any risk? Should I be concerned about this Alert?
Sorry. It is open-ended, very much so. I am trying to get better educated to allow myself to ask better questions. I was looking for something like e.g.:DNS Tunneling - sig 6066/0. If the source address refers to a MS 2003 Server acting as DNS se...
Thanks for the information. I am assumming that most of what I am seeing represents false positives. When you refer to logging, is this a reference to logging on the workstation or server, or are you referring to logging on the IDS device?Thanks,Ti...
Thanks for the information. I must have an old sig set; I thought I was current as of a few weeks ago. I'll update the sig set and confirm that it disables this Alert.