cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1606
Views
0
Helpful
4
Replies

IPS Event Victim IP is 0.0.0.0

ebanzuel23
Level 1
Level 1

Hi Cisco IPS Expert,

I am seeing event in our IPS that shows victim IP is 0.0.0.0.

Some informed that this is a summarized event.

But how can I get details of victim IP if i need to know .

Regards,

Jhun                  

2 Accepted Solutions

Accepted Solutions

rhermes
Level 7
Level 7

You can edit the signature to change the summarization and force it to fire for each victim IP address.

This will result in MANY more signatures firing on your device. Please take this into account if your IPS sensor is already heavily loaded.

http://www.cisco.com/en/US/tech/tk1068/technologies_configuration_example09186a0080c03908.shtml

- Bob

View solution in original post

Juhn -

Yes, anytime you see the 0.0.0.0 address used in the victim IP address field it is the result of multiple victim IP addresses being summarized. I have seen signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event. I'm not sure if all summarized signatures details show this, but that would be the only way I could imagine to see the IP addresses of past events.

- Bob

View solution in original post

4 Replies 4

rhermes
Level 7
Level 7

You can edit the signature to change the summarization and force it to fire for each victim IP address.

This will result in MANY more signatures firing on your device. Please take this into account if your IPS sensor is already heavily loaded.

http://www.cisco.com/en/US/tech/tk1068/technologies_configuration_example09186a0080c03908.shtml

- Bob

Hi Bob,

Thank you for your reponse. I did as instructed. Just waiting for the next even to occur.

So this means I can no longer see the IP details of the victim IP on the previous events.?

Please confirm as well that 0.0.0.0 IP is due to summarization and not as "any host".

-Jhun

Juhn -

Yes, anytime you see the 0.0.0.0 address used in the victim IP address field it is the result of multiple victim IP addresses being summarized. I have seen signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event. I'm not sure if all summarized signatures details show this, but that would be the only way I could imagine to see the IP addresses of past events.

- Bob

Thankf for your help.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card