cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
524
Views
0
Helpful
1
Replies

denyPacketRequestedNotPerformed ?

rand.hall
Level 1
Level 1

The answer seems obvious, but do these "Actions Taken" mean?

denyPacketRequestedNotPerformed, denyFlowRequestedNotPerformed

Why would a requested action not be performed?

1 Accepted Solution

Accepted Solutions

marcabal
Cisco Employee
Cisco Employee

These actions generally are seen on a Promiscuous sensor.

In order to deny the packet or connection the sensor must be deployed inline.

When in promiscuous mode the sensor is not able to deny/drop the actual packets because it is receiving a copy of the packets. What this action lets you know is that if you had deployed it in an inline mode rather than promiscuous mode then the sensor would have protected you from the attack.

The primary purpose for putting this into the alert was to help users who would test the sensor in promiscuous mode before deploying the sensor in inline mode into their network. They would be able to determine what would have been denied. If the alert was a false positive then it would have denied valid traffic on their network if they had placed it inline. So they are able to right a filter for that traffic to ensure it will not be denied before they move the sensor from promiscuous to inline within their network.

View solution in original post

1 Reply 1

marcabal
Cisco Employee
Cisco Employee

These actions generally are seen on a Promiscuous sensor.

In order to deny the packet or connection the sensor must be deployed inline.

When in promiscuous mode the sensor is not able to deny/drop the actual packets because it is receiving a copy of the packets. What this action lets you know is that if you had deployed it in an inline mode rather than promiscuous mode then the sensor would have protected you from the attack.

The primary purpose for putting this into the alert was to help users who would test the sensor in promiscuous mode before deploying the sensor in inline mode into their network. They would be able to determine what would have been denied. If the alert was a false positive then it would have denied valid traffic on their network if they had placed it inline. So they are able to right a filter for that traffic to ensure it will not be denied before they move the sensor from promiscuous to inline within their network.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card