cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
502
Views
0
Helpful
1
Replies

Verify IDS reset connection

jdaw
Level 1
Level 1

I just want to verify that a session was reset when it appears. I have setup a signature to be reset. It shows up as an alarm, just want to make sure the resets are happening.

Thanks,

Joe

1 Reply 1

marcabal
Cisco Employee
Cisco Employee

We don't have a way to currently tell you whether or not the TCP Resets were executed or whether or not they were successful.

It has been requested by users and is being evaluated for inclusion in a future sensor version.

For a workaround you could try the following for a few specific instances:

Set the signature action to both TCP Resets and IPLOG.

Then when the signature fires the connection should be reset. After the signature fires all packets to and from the source address will be IPLOGGED. Then you can check the IPLOG with a program like ethereal (see ww.ethereal.com) to view the packets in the log file. See if any more packets came in on the same connection that the alarm fired on.

Note: There may be several connections from the source address that in the IPLOG file so you will need to check for the same addresses and ports from the connection that created the alarm.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: