‎2010-04-27
02:44 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
CRL-00002
In canned correlation rule CRL-00002, didnot understand the filerset-variable-value, May i know what for the variable set like inout and value set as 1. kindly help me out.
3 Replies
‎2010-04-27
11:13 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
the rule basically looks for inbound connections that is translated by checking if the value of the variable in/out in Firewall devices is equal to
‎2010-04-28
02:46 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
May i know where is parameter set here to filter only the inbound connections?. May i know what is the variable/parameter set i have to go for only to get outbound connections?.
As per my understanding on firewall by checking the ACL group name only we can go for defining inbound/outbound connections and all.
‎2010-04-29
10:46 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
The value of In/Out equals to 1 means inbound connections. Some Firewalls label an inbound connection with the number 1 and the outbound connection with the number 0 but again this depends from a firewall vendor to another. You should check your event logs to see which values they use.
