cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
763
Views
0
Helpful
3
Replies

OS Fingerprinting Question

terrygwazdosky
Level 1
Level 1

I've limited OS mapping and APR to a specific set of IPs (my inside network), but I still see outside IP addresses showing up in the list of learned OS.  is this normal?  I tried clearing out the learned OS list, but am still seeing the outside addresses populating.

I've seen this on 7.03(2)E4 and 7.0(3)E4 and on 3 different units (2 AIP-SSM20s and a 4240).

Thanks.

1 Accepted Solution

Accepted Solutions

Scott Fringer
Cisco Employee
Cisco Employee

This is expected behavior - the setting restircts the calculation of the Attack Relevenacy Rating to the configured range, not the actual OS identification process.

Scott

View solution in original post

3 Replies 3

Scott Fringer
Cisco Employee
Cisco Employee

This is expected behavior - the setting restircts the calculation of the Attack Relevenacy Rating to the configured range, not the actual OS identification process.

Scott

OK, thanks.  The verbage led me to believe it restricted collection of fingerprint data as well.

Yes, it is a confusing phrasing within the IDM GUI.

Scott

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card