Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

VMS SEC MON

Question on VMS 2.3 in the SEC MON(sensor is a IDSM2) events I have notice that on one of my sensors the following Alert Detail: Traffic Source int0(other details show int7 as my source):, is this the TCPRESET port? if so I do not have that SIG set to do this. the SID ID=1203 GFRag Overwrite.

Thanks

2 REPLIES
New Member

Re: VMS SEC MON

what sensor version are you running? the only difference on the alert should be resetTcpFlowSent: true, the sensing interface on the idsm2 remain ge7 and ge8. I'd like to see the entire alert from the cle... show ev al

New Member

Re: VMS SEC MON

Version 4.1(5)S201

Sig Name Sensor Name Alert Details Local Date

CARL322IDSINDIA Frag Overwrite Traffic Source: int0 ; Wed, Nov 09, 2005 02:46:00 PM

here is my config for my SPAN

monitor session 10 source interface Gi1/1 - 2 rx

monitor session 10 source interface Gi2/1 rx

monitor session 10 destination intrusion-detection-module 8 data-port 1

181
Views
0
Helpful
2
Replies
CreatePlease to create content