cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
431
Views
0
Helpful
2
Replies

IPS white list and virus signatures drop

edgar-quintana
Level 1
Level 1

Hi,

Two questions:

1º Is good to drop all high virus signatures?

2º IPS is activated to inside interface, this interface supports vpn conection.

There is activated drop icmp attacks, but sometimes, packets from VPN are dropped.

Is possible to add/create a white list with vpn /lan ip addresses to exclude them from the analisis/drop?

Best regards

2 Replies 2

rhermes
Level 7
Level 7

To answer your second question, you can exclude actions from a particular host with an Event Action Filter. If you're running 6.0 and use the CLI, this is what you'd want to read:

http://cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a00807517b6.html#wp1030749

I use 2821 cisco router

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card