Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
When we tried our MOM interagration we ran into a 512 string limitation in the MARS which makes MOM integration extremely difficult. The last I heard the fix was uncomfirmed for 08. My question is concerning syslog forwarded from an exchange server s...
Hello!We are trying to size a Cisco MARS. Under perfect conditions what is the maxium events that can be generated by an IDSM2?thanks for the help,Geoff
We need to source traffic destined to a partner over a crypto map vpn from the secondary address on an interface.Example.interface fa1/0ip address 155.55.5.1ip address 255.55.5.1 secondarycrypto map somethingWe need to have the source of the traffic ...
Does 12.2(18)SXE2 (6500 sup720/MSFC3) support these blades in the same chassis:Firewall Services Module 2.3(2)Content Service Module 4.2(2)SSL Service Module 2.1(5) App Image/2.1(1) Maint. ImageIDS Service Module 5.0(2)If someone has some exp with th...
Using eudora and Secure Pop we are getting false positives on signature 3550. You can tell in the Hex output that the traffic is encrypted. Any thoughts on how I could tune this to not generate false positives?thanks,geoffhere is a log snip:NEWLOG.lo...
We heard it was slated for 4.2 however that obviously didn't make it in :). I believe the 512 limit is an old protocol limit and several syslog implementations handle larger messages. We have not tried the custom parser yet. However, I was told that ...
Thanks for the response! Actually I disagree. Under perfect conditions what is the number that depicts how fast the device can spit out events. As an example, if the devices can monitor 600 megs of traffic, how many events can it analysis before it d...
Thanks for the message! And thanks for the code version. My problem is that I am hearing horror stories about running all of those blades in the same box. While the 6500 can support running anyone one or two, I need to know if they will all run in th...
I thought the \x was used when indicating Hex strings. Is that incorrect?We changed the string to be exactly what we saw in the snort sig and have been getting hits. But now I am REALLY not sure if we are doing this correclty thanks,GeoffEngine STRI...
No. I mean a session, such as SSH, that is established however no traffic is neing passed on that session. The default time out for idle sessions is 1 hour.Meaning after an hour, if the session is not passing traffic, it will be torn down in the fire...