04-03-2008 02:53 AM - edited 03-10-2019 04:03 AM
I want to exclude some of my network's internal IP addresses as sources. This is a recommended action for some signatures fired on the AIP-SSM of my ASA.
Pls, how and from which of the devices do I exclude the IP addresses.
04-03-2008 11:54 AM
This has become a very popular question. These two threads are within the last 10 posts, but should be able to answer your question
Intrusion Prevention Systems/IDS: IPS - Event Action Filters. Which alerts do you supress -
http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Security&topic=Intrusion%20Prevention%20Systems/IDS&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cbfcac9
Intrusion Prevention Systems/IDS: Tuning signature
http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Security&topic=Intrusion%20Prevention%20Systems/IDS&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc00fea
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
Log in to Community