cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
349
Views
0
Helpful
1
Replies

Basic Sensor Doubts

MannyD123
Level 1
Level 1

Hi all,

I am having some basic doubts regarding the functionality of the sensor.

case 1

------

Assume that sensor is in inline mode.Then

1) By default "stop" atomic attacks

2) By default "stop" attacks that span multiple packets

3) By default block IP address or network addresses without "blocking" being configured?

In the above case how is "stoping" an attack differnet from blocking it?

case 2

------

Assume that sensor is in promiscous mode

1) By default "stop" atomic attacks

2) By default "stop" attacks that span multiple packets

3) By default block IP address or network addresses without "blocking" being configured

Also in this case how is "stoping" an attack different from "blocking" an IP or network address?

Thanks in advance

MD

1 Reply 1

larry.atkins
Level 1
Level 1

Doesn't blocking actually drop all traffic from that IP for a specified period while dropping or stopping means it drops the packets as they are triggered?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: