npham
Level 1
Level 1
Member since ‎05-18-2004
‎08-18-2017

User Statistics

  • 44 Posts
  • 1 Solutions
  • 5 Helpful votes Given
  • 14 Helpful votes Received
Recent Badges
1 Accepted Solution
10 Helpful Vote
1 Helpful Vote
20 Replies
10 Replies
5 Replies

User Activity

Looking to shed some light into the behavior of the Flood Engine.According to Cisco documentation:The Flood engine defines signatures that watch for any host or network sending multiple packets to a single host or network. For example, you can create...
For v4.x sensors, support for Attacker/Victim Loc is defined through setting address ranges in IPS MC > Conf > Settings > Internal Networks (IDS 4.x)After upgrading a 4.x sensor to 5.x, the internal networks (stored in $IN) now show up in Event Varib...
CSA 4.5.1 only lists Sol 8; 5.0 lists up to Sol 9.Is there an expected ETA for support on Solaris 10 or would one of the current CSA versions be okay to use?
Anyone try and modify sig 3002's parameter ResetAfterIdle and notice that no matter what high value you give it, the sig does not fire with a SYN port scan delaying for more than 66 seconds?The default value for sig 3002,ResetAfterIdle = 20Unique = 5...
Sig # 2001 fires when there are ICMP type 3 packets. This message type is more correctly described as Destination Unreachable (refer to IANA).The signature triggers on all type 3 messages, but to be accurate to the NSDB description, it should only t...
Community Statistics
Member Since ‎05-18-2004 10:05 AM
Date Last Visited ‎08-18-2017 03:51 AM
Posts 44
Total Helpful Votes Received 14
Helpful Votes From
Helpful Votes Given To