alerts whitelist src ip <ipAddress>

Prev Next

Suppresses alerts generated from specific IP addresses by adding these IP addresses to the alert whitelist.

The alerts whitelist src ip <ipaddress> command can be used to omit duplicate alerts. For example, when you have two Network Security appliances configured so that one scans for vulnerabilities before a proxy and the second scans for vulnerabilities after a proxy, you may encounter situations where the same IP address is listed twice on the network. You can use this command to whitelist the IP address on the second Network Security appliance so that the IP address is only listed once on the alert screen of the UI.

This command can also be used to suppress alerts for false positives.

This command is specific to Network Security appliances.

Note

When using a Central Management System appliance to manage multiple Network Security appliances, you need to log into individual Network Security appliances to add an IP address to each appliance's alert whitelist.

Syntax

[no] alerts whitelist src ip <ipAddress>

Parameters

no

Use the no form of this command to remove the configuration options currently set.

ipAddress

The source IPv4 or IPv6 IP address to be whitelisted.

Example

The following example adds the specified IP address to the alerts whitelist.

hostname (config) # alerts whitelist src ip 172.1.0.0

The following example removes the specified IP address from the alerts whitelist.

hostname (config) # no alerts whitelist src ip 192.168.1.1

User role

admin, monitor, and operator

Command mode

enable and config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Before release 6.4

  • Email Security — Server: Before release 6.4

  • File Protect: Before release 6.4

  • Endpoint Security (HX): Release 2.5

  • Network Security: Before release 6.4

  • Intelligent Virtual Execution - Server: Before release 6.4