MARS - drop rules

Unanswered Question
Jun 12th, 2007
User Badges:

I have a MARS20 configured to a IPS4240 placed between internet & LAN, and i want to stop my internal network to stop triggering the incidents and stop producing false positive; based on the assumption that my LAN is secure.

So I have created a drop rule to log to DB, source-192.168.0.0 255.255.0.0, remaining parameters as Any.

The rule is active, but i still get incidents w source from LAN.


am i missing something?


Cash

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
mhellman Wed, 06/13/2007 - 05:19
User Badges:
  • Blue, 1500 points or more

did you click "activate"?

Actions

This Discussion