Dec 14 2020
4:49 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dec 14 2020
4:49 PM
MX Advanced Security & SolarWinds breach
Have the FireEye Snort rules to detect SunBurst IOCs been incorporated into MX Advanced Security IDS/IPS?
Solved! Go to solution.
1 Accepted Solution
Dec 14 2020
11:55 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dec 14 2020
11:55 PM
Hi Graham, look into your Event log on the MX and do a search for update. You’ll see that the snort rules have been updated quite a few times recently
Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
5 Replies 5
Dec 14 2020
11:55 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dec 14 2020
11:55 PM
Hi Graham, look into your Event log on the MX and do a search for update. You’ll see that the snort rules have been updated quite a few times recently
Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Dec 15 2020
10:28 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dec 15 2020
10:28 AM
Thanks, Darren. I do see daily snort rule updates.
Dec 19 2020
12:02 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dec 19 2020
12:02 PM
What "event type" do you search for to see this?
Dec 19 2020
12:58 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dec 19 2020
12:58 PM
Hi @ChesterX , see screenshot
Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Dec 19 2020
6:11 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dec 19 2020
6:11 PM
Thank you!

Get notified when there are additional replies to this discussion.