Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

source port 0 with Summarize set to 15

See Sig. ID 5930/0 in IME in Event Monitoring as an example.

If the Alert Frequency, Summary mode of an IPS signature is set to Summarize with a value of 15, does this mean that all 15 hits receive the stated Action Taken (eg. dropped packet, deniedFlow, tcpOneWayResetSent) as in the first alert triggered.

Is it true that the display of 'port 0' in the next triggered event represents the following 14 events which also experience the same action taken as the first, but the Actions Taken words (dropped packet, deniedFlow, tcpOneWayResetSent) are not displayed (ie. the field is blank).

Can someone clear this up for me?

Thanks.

WG

Everyone's tags (2)
1 REPLY
Cisco Employee

source port 0 with Summarize set to 15

Hi,

Yes, actually what will happen is that after X amount of events (times triggered the signature) on an X amount of time you will see an event generated.

The action will be the same for all events (times triggered the signature) but message will only display after X amount of events

http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/clisgdef.html#wp1040171

HTH

Luis Silva

"If you need PDI (Planning, Design, Implement) assistance feel free to reach us"

http://www.cisco.com/web/partners/tools/pdihd.html

Luis Silva "If you need PDI (Planning, Design, Implement) assistance feel free to reach us" http://www.cisco.com/web/partners/tools/pdihd.html
381
Views
0
Helpful
1
Replies
CreatePlease to create content