RSA Admin

How to filter a network of IPs

Discussion created by RSA Admin Employee on Oct 3, 2011
Latest reply on Nov 15, 2011 by RSA Admin
Hi, I have created a correlation rule where I would like to create alerts when usernames from outside a specific network login to a F5 Firepass device. I am performing multithreading based on the username. The problem that I am facing is that I cannot add a network of IPs in the filter section of the correlation statement. I have tried with one IP and it works but I tried putting 10.24.12.20/24 but this didn;t work. How can I add a whole network to be excluded from the correlation rule? Thanks, Eleni

Outcomes