Specifying source IP addresses and ports

When you specify a rule's event source, you are associating events with specific source IP addresses or ports. The Central Responses server only generates a response if the event source matches an IP address and port you specified.


  1. In the Add Event Rules window, select the Source tab.
  2. To include events from all IP addresses, select Any. Otherwise, select Use Specific Source Address, and then select a Mode from the list:
    Option Description
    From Includes events only from the IP addresses you specify
    Not From Excludes events from the IP addresses you specify
  3. In the Specific Sources section, select one of the following options:
    Option Description
    IP Address List Applies the rule to specific IP addresses
    Network Address/#Network Bits (CIDR) Applies the rule to a block of IP addresses.
    Value: The entry after the slash is the prefix length and is a number from 1 to 32. Example:
    IP Address Range Applies the rule to IP addresses within a specified range.
    Important: Do not use as the Site range. If you use this as the Site range, random IP addresses are added to your ungrouped assets folder, such as IP addresses from Web sites.
    Address List Entry Applies the rule to a Network Object Address Name selected from the list.
    Tip: To create a new Address Name to include here, click Add Address Name. The Select Network Object window appears and enables you to create a new list entry.
  4. In the Source Port section, select one of the following options:
    Option Description
    Any Includes all ports in your Site
    Single Port Includes a single port in your Site
    Port Range Includes a specified range of ports
    Value: 0 to 65535.
    Port List Entry Includes a Network Object Port Name.