[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [ISSForum] Realsecure Server Sensor - Network Filtering



I would have to respectfully disagree..

>From the Blackice Advanced Administration Gudie..

trust.pair
Description This parameter defines IP address-signature pairs that an agent
ignores. An agent ignores
a specific attack from a specific IP address.
Values IP address (or range) and signature pairs
Default none
Example trust.pair = 192.68.0.1,2002703

You would just have to find the issue id for the event you were interested
in; once you find that, once you find that, you can edit the blackice.ini
file with the above information.

Hope this helps..

-----Original Message-----
From: issforum-bounces@xxxxxxx [mailto:issforum-bounces@xxxxxxx]On
Behalf Of dmsimpson@xxxxxxx
Sent: Friday, October 08, 2004 6:49 AM
To: Michael Nurre
Cc: issforum-bounces@xxxxxxx; issforum@xxxxxxx
Subject: Re: [ISSForum] Realsecure Server Sensor - Network Filtering


No you cannot.  I have actually been requesting this from ISS for a little 
over three years.

Thanks,

David M Simpson
Risk Management Enterprise Security
Intrusion Detection Lead
American Electric Power
614.716.3139
dmsimpson@xxxxxxx




"Michael Nurre" <mnurre@xxxxxxxxxxxxxxxx>
Sent by: issforum-bounces@xxxxxxx
10/07/2004 03:48 PM

 
        To:     issforum@xxxxxxx
        cc: 
        Subject:        [ISSForum] Realsecure Server Sensor - Network
Filtering


Does anyone know if it is possible to filter out specific IP addresses for 

different signatures on the Server Sensor 7.0 like you can with the 
Network Sensor? I would think it possible by editing some of the ini files 

under the BlackIce directory on the server sensor installation.
_______________________________________________
ISSForum mailing list
ISSForum@xxxxxxx

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to mod-issforum@xxxxxxx

The ISSForum mailing list is hosted and managed by Internet Security 
Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.


_______________________________________________
ISSForum mailing list
ISSForum@xxxxxxx

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to mod-issforum@xxxxxxx

The ISSForum mailing list is hosted and managed by Internet Security
Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.

**************************************************************************************************
Note:          
The information contained in this message may be privileged and confidential and 
protected from disclosure.  If the reader of this message is not the intended recipient, 
or an employee or agent responsible for delivering this message to the intended 
recipient, you are hereby notified that any dissemination, distribution or copying of this 
communication is strictly prohibited. If you have received this communication in error, 
please notify us immediately by replying to the message and deleting it from your 
computer. 
**************************************************************************************************
_______________________________________________
ISSForum mailing list
ISSForum@xxxxxxx

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to mod-issforum@xxxxxxx

The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.