Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IDS: "Never Block Addresses" Not Working

Cisco IDS 4210 v3.1(3)

PIX 515 v6.2(2)

Using IDM, I've setup the "Never Block Addresses" to never block certain internal IP's.

It doesn't work. I'm still seeing these IP's get blocked on occaision due to "false positives".

I've done as instructed: use 255.255.255.255 as the subnet mask of a host. I've also tried setting up to never block our entire internal network using the network address. No joy.

Any suggestions?

Tony

1 REPLY
Silver

Re: IDS: "Never Block Addresses" Not Working

The format that you would need to use is the IP address, subnet mask (eg /24) and comments in the Enter Network page.

Please refer to the configuration details:

http://www.cisco.com/en/US/products/sw/cscowork/ps3990/products_user_guide_chapter09186a0080104f44.html#xtocid17

As far as my knowledge goes, In the 'Never Block Addresses' category, you would need to enter internal network addresses, DMZ addresses and global addresses. I also guess that the IDS sensing interface would not see the internal and DMZ addresses though. And also if the sensor is sniffing traffic on the outside, you would have to specify the public addresses for the addresses that you dont want to block.

Hope this helps.

81
Views
0
Helpful
1
Replies