cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
390
Views
0
Helpful
2
Replies

MARS Exclusions?

anthonysgroi
Level 1
Level 1

Is there a way to exclude certain IP Address's from mars? For instance i want to exclude the 200 events that Nessus scans produce, i cant seem to find a way to do this. Any help would be great thanks.

1 Accepted Solution

Accepted Solutions

Please take mhellman's advice and read the Users Guide to get a better understanding of how Drop Rules work.

Though even better than the Users Guide is the book from Cisco Press, "Security Threat Mitigation and Response" by Dale Tesch. You should also certainly read the Users Guide but sometimes a second source helps to improve your understanding of a security device like MARS.

Hope this helps.

View solution in original post

2 Replies 2

mhellman
Level 7
Level 7

yes, it is called a drop rule. Have you read the users guide yet?...it's in there. You can completely drop the events or just "log to db" (don't process inspection rules).

Please take mhellman's advice and read the Users Guide to get a better understanding of how Drop Rules work.

Though even better than the Users Guide is the book from Cisco Press, "Security Threat Mitigation and Response" by Dale Tesch. You should also certainly read the Users Guide but sometimes a second source helps to improve your understanding of a security device like MARS.

Hope this helps.

Review Cisco Networking products for a $25 gift card