cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
737
Views
0
Helpful
1
Replies

Exemption specific intrusion rule for host

ashaw216
Level 1
Level 1

      Here is what I'm trying to do: we have a edge mail appliance that is receiving bounce emails that are being detected as SMTP_RESPONSE_OVERFLOW.  I'd like to be able to ignore this detection for that host, but I don't see an easy way to do this.

 

I'm coming to FP IPS from a Juniper perspective, where adding an exemption for a specific detection for a specific host involved a right-click and Allow on the traffic. This doesn't appear to be that easy. Do I really have to create a completely separate Access Control policy, with a completely separate Intrusion policy, just to be able to do this?

 

1 Reply 1

ashaw216
Level 1
Level 1

Does no one use FP IPS, or no one reads the board, or is Cisco Support Community not as much into the Support aspect as it used to be?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card