Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IPS Event Victim IP is 0.0.0.0

Hi Cisco IPS Expert,

I am seeing event in our IPS that shows victim IP is 0.0.0.0.

Some informed that this is a summarized event.

But how can I get details of victim IP if i need to know .

Regards,

Jhun                  

2 ACCEPTED SOLUTIONS

Accepted Solutions
Gold

IPS Event Victim IP is 0.0.0.0

You can edit the signature to change the summarization and force it to fire for each victim IP address.

This will result in MANY more signatures firing on your device. Please take this into account if your IPS sensor is already heavily loaded.

http://www.cisco.com/en/US/tech/tk1068/technologies_configuration_example09186a0080c03908.shtml

- Bob

Gold

IPS Event Victim IP is 0.0.0.0

Juhn -

Yes, anytime you see the 0.0.0.0 address used in the victim IP address field it is the result of multiple victim IP addresses being summarized. I have seen signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event. I'm not sure if all summarized signatures details show this, but that would be the only way I could imagine to see the IP addresses of past events.

- Bob

4 REPLIES
Gold

IPS Event Victim IP is 0.0.0.0

You can edit the signature to change the summarization and force it to fire for each victim IP address.

This will result in MANY more signatures firing on your device. Please take this into account if your IPS sensor is already heavily loaded.

http://www.cisco.com/en/US/tech/tk1068/technologies_configuration_example09186a0080c03908.shtml

- Bob

New Member

IPS Event Victim IP is 0.0.0.0

Hi Bob,

Thank you for your reponse. I did as instructed. Just waiting for the next even to occur.

So this means I can no longer see the IP details of the victim IP on the previous events.?

Please confirm as well that 0.0.0.0 IP is due to summarization and not as "any host".

-Jhun

Gold

IPS Event Victim IP is 0.0.0.0

Juhn -

Yes, anytime you see the 0.0.0.0 address used in the victim IP address field it is the result of multiple victim IP addresses being summarized. I have seen signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event. I'm not sure if all summarized signatures details show this, but that would be the only way I could imagine to see the IP addresses of past events.

- Bob

New Member

IPS Event Victim IP is 0.0.0.0

Thankf for your help.

875
Views
0
Helpful
4
Replies