smartvision alert allowlist

Prev Next

Adds or removes a SmartVision alerts allowlist entry. If a SmartVision event matches all the conditions specified in any allowlist entry, no SmartVision notifications are generated and no events are logged in the SmartVision database.

SmartVision appliances are described in the Network Security SmartVision Feature Guide

The SmartVision alerts allowlist is empty by default.

Note

You can also run this command remotely from the command line of an integrated TrellixCentral Management System appliance using the central management appliance proxying mechanism.

Syntax

[no] smartvision alert whitelist <conditions>

Parameters

no

Use the no form of the command to remove the SmartVision alerts allowlist entry that consists of specified combination of conditions.

<conditions>

A combination of any of the following conditions for allowlisting SmartVision alerts:

dest <ip address>/<prefix>

An IPv4 or IPv6 destination address range.

rule <ruleID>

A SmartVision rule ID.

source <ip address>/<prefix>

An IPv4 or IPv6 source address range.

Examples

The following command adds a SmartVision alerts allowlist entry that combines a SmartVision rule ID and an IPv6 source address block:

smartvision alert whitelist rule 91500079 source 2001:db8:701f::/48

The following command removes a SmartVision alerts allowlist entry that combines a SmartVision rule ID and an IPv4 destination address block:

no smartvision alert whitelist dest 192.168.4.0/24 rule 91500079

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.0