[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [ISSForum] Realsecure Server Sensor - Network Filtering



Unfortunately that filtering method is for the BlackICE (Desktop 
Protector) client and not for RealSecure Server Sensor. 

Thanks,

David M Simpson
Risk Management Enterprise Security
Intrusion Detection Lead
American Electric Power
614.716.3139
dmsimpson@xxxxxxx




"Anderson, Mike" <Mike_Anderson@xxxxxxxxxxxxxxxxxxxxx>
10/08/2004 09:02 AM

 
        To:     "'dmsimpson@xxxxxxx'" <dmsimpson@xxxxxxx>, Michael Nurre 
<mnurre@xxxxxxxxxxxxxxxx>
        cc:     issforum@xxxxxxx
        Subject:        RE: [ISSForum] Realsecure Server Sensor - Network Filtering


I would have to respectfully disagree.. 
>From the Blackice Advanced Administration Gudie.. 
trust.pair 
Description This parameter defines IP address-signature pairs that an 
agent ignores. An agent ignores 
a specific attack from a specific IP address. 
Values IP address (or range) and signature pairs 
Default none 
Example trust.pair = 192.68.0.1,2002703 
You would just have to find the issue id for the event you were interested 
in; once you find that, once you find that, you can edit the blackice.ini 
file with the above information.
Hope this helps.. 
-----Original Message----- 
From: issforum-bounces@xxxxxxx [mailto:issforum-bounces@xxxxxxx]On 
Behalf Of dmsimpson@xxxxxxx 
Sent: Friday, October 08, 2004 6:49 AM 
To: Michael Nurre 
Cc: issforum-bounces@xxxxxxx; issforum@xxxxxxx 
Subject: Re: [ISSForum] Realsecure Server Sensor - Network Filtering 

No you cannot.  I have actually been requesting this from ISS for a little 

over three years. 
Thanks, 
David M Simpson 
Risk Management Enterprise Security 
Intrusion Detection Lead 
American Electric Power 
614.716.3139 
dmsimpson@xxxxxxx 



"Michael Nurre" <mnurre@xxxxxxxxxxxxxxxx> 
Sent by: issforum-bounces@xxxxxxx 
10/07/2004 03:48 PM 
  
        To:     issforum@xxxxxxx 
        cc: 
        Subject:        [ISSForum] Realsecure Server Sensor - Network 
Filtering 

Does anyone know if it is possible to filter out specific IP addresses for 

different signatures on the Server Sensor 7.0 like you can with the 
Network Sensor? I would think it possible by editing some of the ini files 

under the BlackIce directory on the server sensor installation. 
_______________________________________________ 
ISSForum mailing list 
ISSForum@xxxxxxx 
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum 
To contact the ISSForum Moderator, send email to mod-issforum@xxxxxxx 
The ISSForum mailing list is hosted and managed by Internet Security 
Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328. 

_______________________________________________ 
ISSForum mailing list 
ISSForum@xxxxxxx 
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum 
To contact the ISSForum Moderator, send email to mod-issforum@xxxxxxx 
The ISSForum mailing list is hosted and managed by Internet Security 
Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.

**************************************************************************************************
Note: 
The information contained in this message may be privileged and 
confidential and 
protected from disclosure.  If the reader of this message is not the 
intended recipient, 
or an employee or agent responsible for delivering this message to the 
intended 
recipient, you are hereby notified that any dissemination, distribution or 
copying of this 
communication is strictly prohibited. If you have received this 
communication in error, 
please notify us immediately by replying to the message and deleting it 
from your 
computer. 
**************************************************************************************************


_______________________________________________
ISSForum mailing list
ISSForum@xxxxxxx

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to mod-issforum@xxxxxxx

The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.