Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IDS 4.0 - filtering signatures

Has successfully filtered signatues with IDS version 4.0? After I set up a filter, as I normally would in version3.1, and restart the services, the IDS still sends alarms for the filtered signature. Here is how I set up the t he filter.

1. Log on to IDM

2. Go to Configuration

3. Go to Sensing Engine

4. Click on event filters

5. Click add

6. Enter the following info:

SIGID: 5365

SubSig: *

Exception - unchecked

SrcAddrs: 10.0.0.0/24 (example)

DestAddrs: *

Shouldn't this filter sig 5365 with any address sourcing from 10.0.0.0 255.255.255.0 ?

1 REPLY
Cisco Employee

Re: IDS 4.0 - filtering signatures

This is all it takes. I'm sure you did save the changes and applied to the sensor.

Thanks,

yatin

94
Views
0
Helpful
1
Replies