Cisco Cisco IPS 4255 Sensor Weißbuch
Overview
© 2008 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information.
Page 7 of 7
Summary
Not all IPS alerts are actionable. Using Cisco IPS Manager Express, you can easily filter out
benign alerts and focus on the alerts that could be attacks on your network. If you find an attack
that wasn’t dropped, you can use a single click to examine the intelligence about the alert, which
will help you to decide if you need to take action on the victim or source host. You can also modify
IPS policy to give you more information about alerts; this will give you more data to help your
forensics investigation.
If you need assistance with tuning or forensics research, Cisco offers two options for customers:
Cisco Professional Services and Cisco Remote Operation Services (
http://www.cisco.com/go/ros
).
Printed in USA
C17-464691-00 04/08