By default, alert notifications use src/smac/sport for the network traffic source and use dst/dmac/dport as the network traffic destination. This command changes alert notifications to use src/smac/sport as the network traffic destination (victim) and use dst/dmac/dport as the network traffic source (attacker). This command affects all notification data formats. This command applies only to IPS-enabled appliances (Network Security and Central Management System).
Syntax
[no] fenotify preferences normalize-ips-event enable
Parameters
no
Use the no form of this command to change alert notifications to use src/smac/sport as the network traffic destination (victim) and use dst/dmac/dport as the network traffic source (attacker).
Example
The following example returns alert notifications to the default, using src/smac/sport for the network traffic source and using dst/dmac/dport as the network traffic destination:
hostname (config) # fenotify preferences normalize-ips-event enable
User role
Admin and Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.8
Endpoint Security (HX): Release 3.5.0
Network Security: Release 7.8