Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Tuning issue with false positive

One of my clients moved two of their email devices to a DMZ. The both produce alerts on the mass mailing worm alert. Before they were moved to the DMZ, you would see the alert and it would have a source and destination IP. Now it only has the destination IP address of where the device is sending email to. Since the MARS does not pick up the devices new IP address, I cannot false positive tune these alerts out. How would I go about fixing this issue?

2 REPLIES
Silver

Re: Tuning issue with false positive

When the IDS mistakenly thinks that normal traffic is malicious then false positives happen To reduce them you have to fine tune the system by letting it know what normal traffic means on your network.

Cisco has provided some great guidance on how to reduce false positives here:

http://www.cisco.com/en/US/products/ps6241/products_user_guide_chapter09186a008072f396.html#wp1030968

Silver

Re: Tuning issue with false positive

I agree 100% with Anthony. You must tune the IDS and reduce the false positives at the source, not try to tune them on MARS.

A "5" from NYC.

158
Views
5
Helpful
2
Replies