cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
403
Views
0
Helpful
1
Replies

Global Correlation Reputation Filtering questions

clausonna
Level 3
Level 3

The IPS 7.x docs state that with Reputation Filtering enabled "the sensor denies access to malicious hosts that are listed in the Global Correlation database." So I assume that means that even if no signatures are matched/triggered, the mere fact that the destination IP address is in the GC will drop the packet.

If so, does this happen silently, or is an event/alert created? If its silent, is the "ReputationFilterRuleMatch" stat from the "show stat analysis" command on the sensor the right place to look?

1 Reply 1

mkodali
Cisco Employee
Cisco Employee

For malicious hosts listed in Global correlation database the right place to look will be "show statistics analysis-engine" and observe counters for TcpDeniesDueToGlobalCorrelation. If sensor is not in inline mode then the counters will SimulatedTcpDeniesDueToGlobalCorrelation. No events are generated for these denies.

Please note that these counters are cumulative and not reset until sensor is restarted.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card