01-30-2003 11:29 AM - edited 03-09-2019 01:54 AM
When one configures blocking on an IDS 4210 v3.1, what severity level triggers the block?
I assume HIGH, but one must never assume.
In IDM, I haven't seen anywhere to configure this.
Solved! Go to Solution.
01-30-2003 12:01 PM
It's not based on the severity. You can use the block feature on a low priority alarm if you want to. You need to set it at the signature level. When you enable a signature and set its priority you also set the signature action, which includes the block function.
Hope that helps.
01-30-2003 12:23 PM
I haven't seen a way to group them. I've been doing it individually.
Pete
01-30-2003 12:01 PM
It's not based on the severity. You can use the block feature on a low priority alarm if you want to. You need to set it at the signature level. When you enable a signature and set its priority you also set the signature action, which includes the block function.
Hope that helps.
01-30-2003 12:14 PM
>>...You need to set it at the signature level...<<
Ah yes, I see that now. I hadn't delved far enough into IDM yet.
That brings up another question: Must I configure blocking for each individual signature or can I do it for groups?
A quick glance looks like I must go through each signature and select this.
Thanks for your help.
Tony
01-30-2003 12:23 PM
I haven't seen a way to group them. I've been doing it individually.
Pete
01-30-2003 01:06 PM
Bummer...
Well, I get paid by the hour so...
Tony
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide