Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

CSA rule for remote DB access attempt

I have created a File Access Control rule as follows:

- Take the following action: Monitor

- when Applications in any of the following selected classes: <Remote Clients>

- But not in any of the following selected classes: <none.

- Attempt the following operations: Write File

- On any of these files:

**\*.?db

**\*.db?

**\*.db

This rule is actually working quite well so far, but I would like to make it more precise. Is there any way I can create an Application Class for just the Admin Shares (c$, admin$, etc.)? I don't want it trippin on open Network Shares.

1 REPLY
Silver

Re: CSA rule for remote DB access attempt

102
Views
0
Helpful
1
Replies
CreatePlease to create content