denyPacketRequestedNotPerformed ?

Answered Question
Jul 8th, 2009
User Badges:

The answer seems obvious, but do these "Actions Taken" mean?


denyPacketRequestedNotPerformed, denyFlowRequestedNotPerformed


Why would a requested action not be performed?

Correct Answer by marcabal about 7 years 11 months ago

These actions generally are seen on a Promiscuous sensor.

In order to deny the packet or connection the sensor must be deployed inline.


When in promiscuous mode the sensor is not able to deny/drop the actual packets because it is receiving a copy of the packets. What this action lets you know is that if you had deployed it in an inline mode rather than promiscuous mode then the sensor would have protected you from the attack.

The primary purpose for putting this into the alert was to help users who would test the sensor in promiscuous mode before deploying the sensor in inline mode into their network. They would be able to determine what would have been denied. If the alert was a false positive then it would have denied valid traffic on their network if they had placed it inline. So they are able to right a filter for that traffic to ensure it will not be denied before they move the sensor from promiscuous to inline within their network.


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
marcabal Wed, 07/08/2009 - 07:47
User Badges:
  • Cisco Employee,

These actions generally are seen on a Promiscuous sensor.

In order to deny the packet or connection the sensor must be deployed inline.


When in promiscuous mode the sensor is not able to deny/drop the actual packets because it is receiving a copy of the packets. What this action lets you know is that if you had deployed it in an inline mode rather than promiscuous mode then the sensor would have protected you from the attack.

The primary purpose for putting this into the alert was to help users who would test the sensor in promiscuous mode before deploying the sensor in inline mode into their network. They would be able to determine what would have been denied. If the alert was a false positive then it would have denied valid traffic on their network if they had placed it inline. So they are able to right a filter for that traffic to ensure it will not be denied before they move the sensor from promiscuous to inline within their network.


Actions

This Discussion