cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
343
Views
0
Helpful
4
Replies

IDS: At What Severity Level Does Blocking Occur?

tscislaw_2
Level 1
Level 1

When one configures blocking on an IDS 4210 v3.1, what severity level triggers the block?

I assume HIGH, but one must never assume.

In IDM, I haven't seen anywhere to configure this.

2 Accepted Solutions

Accepted Solutions

pdentico
Level 1
Level 1

It's not based on the severity. You can use the block feature on a low priority alarm if you want to. You need to set it at the signature level. When you enable a signature and set its priority you also set the signature action, which includes the block function.

Hope that helps.

View solution in original post

I haven't seen a way to group them. I've been doing it individually.

Pete

View solution in original post

4 Replies 4

pdentico
Level 1
Level 1

It's not based on the severity. You can use the block feature on a low priority alarm if you want to. You need to set it at the signature level. When you enable a signature and set its priority you also set the signature action, which includes the block function.

Hope that helps.

>>...You need to set it at the signature level...<<

Ah yes, I see that now. I hadn't delved far enough into IDM yet.

That brings up another question: Must I configure blocking for each individual signature or can I do it for groups?

A quick glance looks like I must go through each signature and select this.

Thanks for your help.

Tony

I haven't seen a way to group them. I've been doing it individually.

Pete

Bummer...

Well, I get paid by the hour so...

Tony