I have my IPS reporting to MARS and I am currently getting a lot of events that are being caused by metacomponents. It is my understanding that these metacomponents should not be producing any events/alerts.
This is occurring with a number of signatures. Have doubled checked that the signatures are in their default state with no actions defined.
Anyone know where I should start looking or is this the correct behavior.
One of the signature engine of IPS 6.0 is Meta engine.
Meta-Defines events that occur in a related manner within a sliding time interval. This engine processes events rather than packets. As signature events are generated, the Meta engine inspects them to determine if they match any or several Meta definitions. The Meta engine generates a signature event after all requirements for the event are met.
All signature events are handed off to the Meta engine by SEAP. SEAP hands off the event after processing the minimum hits option. Summarization and event action are processed after the Meta engine has processed the component events.
But the large number of Meta signatures could adversely affect overall sensor performance. You can remove the actions as metacomponents are not to be edited.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...