Hi,

I have problem with configuring Realsecure packet filter.
On policy that is acitve on my sensors I configured  "User-specified
filter" for address 172.16.10.10 which is our penetration-test machine.
(enabled, src address:172.16.10.10, dest address:any, protocol ip,tcp,udp,
icmp (that is four filters), src service/type:any, dest service/type:any).
After that I applied policy on sensors.
But although I have enabled packet filters on sensors, host 172.16.10.10
still appears on Realsecure console, and logs that events into a database.

Is it posible to filter out events from single IP address to all other
addresses, and ports(e.i. from ip 172.16.10.10)?

I have Realsecure console ver 6.7., collector ver 6.5., and two sensors
Nokia ver 7.0.

Thanks in advance

Antonio

--
Sudjelujte u Iskon Bonus nagradnom programu i osvajajte nagrade.
Saznajte vi�e na web adresi http://www.iskon.biz/bonus/
_______________________________________________
ISSForum mailing list
[EMAIL PROTECTED]

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to 
https://atla-mm1.iss.net/mailman/listinfo

Reply via email to