Unfortunately that filtering method is for the BlackICE (Desktop
Protector) client and not for RealSecure Server Sensor.
Thanks,
David M Simpson
Risk Management Enterprise Security
Intrusion Detection Lead
American Electric Power
614.716.3139
[EMAIL PROTECTED]
"Anderson, Mike" <[EMAIL PROTECTED]>
10/08/2004 09:02 AM
To: "'[EMAIL PROTECTED]'" <[EMAIL PROTECTED]>, Michael Nurre
<[EMAIL PROTECTED]>
cc: [EMAIL PROTECTED]
Subject: RE: [ISSForum] Realsecure Server Sensor - Network Filtering
I would have to respectfully disagree..
>From the Blackice Advanced Administration Gudie..
trust.pair
Description This parameter defines IP address-signature pairs that an
agent ignores. An agent ignores
a specific attack from a specific IP address.
Values IP address (or range) and signature pairs
Default none
Example trust.pair = 192.68.0.1,2002703
You would just have to find the issue id for the event you were interested
in; once you find that, once you find that, you can edit the blackice.ini
file with the above information.
Hope this helps..
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
Behalf Of [EMAIL PROTECTED]
Sent: Friday, October 08, 2004 6:49 AM
To: Michael Nurre
Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED]
Subject: Re: [ISSForum] Realsecure Server Sensor - Network Filtering
No you cannot. I have actually been requesting this from ISS for a little
over three years.
Thanks,
David M Simpson
Risk Management Enterprise Security
Intrusion Detection Lead
American Electric Power
614.716.3139
[EMAIL PROTECTED]
"Michael Nurre" <[EMAIL PROTECTED]>
Sent by: [EMAIL PROTECTED]
10/07/2004 03:48 PM
To: [EMAIL PROTECTED]
cc:
Subject: [ISSForum] Realsecure Server Sensor - Network
Filtering
Does anyone know if it is possible to filter out specific IP addresses for
different signatures on the Server Sensor 7.0 like you can with the
Network Sensor? I would think it possible by editing some of the ini files
under the BlackIce directory on the server sensor installation.
_______________________________________________
ISSForum mailing list
[EMAIL PROTECTED]
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
https://atla-mm1.iss.net/mailman/listinfo/issforum
To contact the ISSForum Moderator, send email to [EMAIL PROTECTED]
The ISSForum mailing list is hosted and managed by Internet Security
Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
_______________________________________________
ISSForum mailing list
[EMAIL PROTECTED]
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
https://atla-mm1.iss.net/mailman/listinfo/issforum
To contact the ISSForum Moderator, send email to [EMAIL PROTECTED]
The ISSForum mailing list is hosted and managed by Internet Security
Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
**************************************************************************************************
Note:
The information contained in this message may be privileged and
confidential and
protected from disclosure. If the reader of this message is not the
intended recipient,
or an employee or agent responsible for delivering this message to the
intended
recipient, you are hereby notified that any dissemination, distribution or
copying of this
communication is strictly prohibited. If you have received this
communication in error,
please notify us immediately by replying to the message and deleting it
from your
computer.
**************************************************************************************************
_______________________________________________
ISSForum mailing list
[EMAIL PROTECTED]
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
https://atla-mm1.iss.net/mailman/listinfo/issforum
To contact the ISSForum Moderator, send email to [EMAIL PROTECTED]
The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303
Barfield Road, Atlanta, Georgia, USA 30328.