01-08-2002 10:38 AM - edited 03-08-2019 09:31 PM
I cannot get one of my sensors to IGNORE any form of traffic tripping signature 3030. I have tried individual hosts for filtering, entire networks, and finally the entire sig. Here is the entry in my SigSettings.conf:
RecordOfExcludedPattern 3030 * * *
Am I missing something here? Why am I still seeing alarms???
Thx,
brkn!
01-08-2002 11:56 AM
What version of the sensor SW are you running? There are known problems in the 3.0(2) and 3.0(1) code with Exclusions and sweeps. These have all been corrected in 3.0(3). If you are running 3.0(3) and are still experiencing difficulties then we need to talk off-line so that we can get to the root of the problem. You can e-mail me direct at klwiley@cisco.com.
01-08-2002 12:51 PM
I was running 3.0(2), upgraded to current and everything is working well. Probably should have tried that from the start, but it did not exhibit this behavior immediately after my initial upgrade (from 2.x to 3.x), seemed odd -- thanks for the help.
-brkn!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide