Hi, I have problem with configuring Realsecure packet filter. On policy that is acitve on my sensors I configured "User-specified filter" for address 172.16.10.10 which is our penetration-test machine. (enabled, src address:172.16.10.10, dest address:any, protocol ip,tcp,udp, icmp (that is four filters), src service/type:any, dest service/type:any). After that I applied policy on sensors. But although I have enabled packet filters on sensors, host 172.16.10.10 still appears on Realsecure console, and logs that events into a database.
Is it posible to filter out events from single IP address to all other addresses, and ports(e.i. from ip 172.16.10.10)? I have Realsecure console ver 6.7., collector ver 6.5., and two sensors Nokia ver 7.0. Thanks in advance Antonio -- Sudjelujte u Iskon Bonus nagradnom programu i osvajajte nagrade. Saznajte vi�e na web adresi http://www.iskon.biz/bonus/ _______________________________________________ ISSForum mailing list [EMAIL PROTECTED] TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo
