Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

SSM-IPS 6.03E1 unwanted blocking

Hi all,

I am doing some testing in the lab and came accross something that is interesting to me:

I enabled sigs 2000 and 2004 to test that the ips is inspecting the traffic and checked the action for those 2 sigs as producealert only. That worked well with informational alert sev. However, when raisng the sev to high the IPS starts blocking the icmp packets even though the action on the signature is only produce alert. Why is the IPS blocking such traffic? Am I missing something here. As always, help is appreciated.

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: SSM-IPS 6.03E1 unwanted blocking

There is a default event-action-override for deny-packet-inline that gets added to all events with a Risk Rating of 90 or higher.

When running setup on the sensor, one of the last questions is "Modify default threat prevention settings?[no]".

If you answer "no" then the default remains active. Your 2000, and 2004 signatures will generate Risk Rating higher than 90 if you change the severity to high, and so will be automatically denied.

If you answer "yes" then you are provided to option to disable these default settings.

To see this setup option refer to step 20 of this section:

http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/cli/cli_initializing.html#wp1072155

To learn more about event action overrides refer to:

http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/cli/cli_event_action_rules.html#wp1085984

2 REPLIES
Cisco Employee

Re: SSM-IPS 6.03E1 unwanted blocking

There is a default event-action-override for deny-packet-inline that gets added to all events with a Risk Rating of 90 or higher.

When running setup on the sensor, one of the last questions is "Modify default threat prevention settings?[no]".

If you answer "no" then the default remains active. Your 2000, and 2004 signatures will generate Risk Rating higher than 90 if you change the severity to high, and so will be automatically denied.

If you answer "yes" then you are provided to option to disable these default settings.

To see this setup option refer to step 20 of this section:

http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/cli/cli_initializing.html#wp1072155

To learn more about event action overrides refer to:

http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/cli/cli_event_action_rules.html#wp1085984

New Member

Re: SSM-IPS 6.03E1 unwanted blocking

Thank you. That's what I wanted to hear.

121
Views
0
Helpful
2
Replies