Issue with Log Generation in Cisco Meraki IDS and IDPS Testing

Akash01
New here

Issue with Log Generation in Cisco Meraki IDS and IDPS Testing

We are currently testing the Intrusion Detection System (IDS) and Intrusion Prevention System (IDPS) capabilities of our Cisco Meraki setup, specifically by conducting port scanning of our network IP. However, we've encountered an issue where no logs are being generated on the portal, even after conducting multiple types of attacks in a controlled environment. Could you please advise if there is a setting or configuration we might be overlooking?

3 Replies 3
RaphaelL
Kind of a big deal
Kind of a big deal
alemabrahao
Kind of a big deal
Kind of a big deal

Did you change your filter to include all logs?

 

alemabrahao_0-1716403819997.png

 

I will confess that I was once embarrassed by a client because the feature didn't work as expected. We simulated several types of attacks and none were blocked.

We got to involve Meraki and it never worked as expected. So in short, the customer gave up on the product.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

>specifically by conducting port scanning of our network IP

 

Port scanning won't trigger anything.  You'll need to try an actual exploit.  Metasploit is a well known popular tool for doing this kind of thing.

https://www.metasploit.com/

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels