Configuring Event Action Filters - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Event Action Filters
When filtering sweep signatures, we recommend that you do not filter the destination addresses. If there
Note
are multiple destination addresses, only the last address is used for matching the filter.
Event action filters based on source and destination IP addresses do not function for the Sweep engine,
Caution
because they do not filter as regular signatures. To filter source and destination IP addresses in sweep
alerts, use the source and destination IP address filter parameters in the Sweep engine signatures.

Configuring Event Action Filters

You can configure event action filters to remove specific actions from an event or to discard an entire
event and prevent further processing by the sensor. You can use event action variables that you defined
to group addresses for your filters. For the procedure for configuring event action variables, see
Configuring Event Action Variables, page
You must preface the variable with a dollar sign ($) to indicate that you are using a variable rather than
Note
a string. Otherwise, you receive the
Use the filters [edit | insert | move] name1 [begin | end | inactive | before | after] command in service
event action rules submode to set up event action filters.
To configure event action filters, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Step 2
Enter event action rules submode:
sensor# configure terminal
sensor(config)# service event-action-rules rules0
Create the filter name:
Step 3
sensor(config-rul)# filters insert name1 begin
Use name1, name2, and so forth to name your event action filters. Use the begin | end | inactive | before
| after keywords to specify where you want to insert the filter.
Configure the values for this filter:
Step 4
a.
b.
c.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
6-10
Set the signature ID range:
sensor(config-rul-fil)# signature-id-range 1000-1005
The default is 900 to 65535.
Set the subsignature ID range:
sensor(config-rul-fil)# subsignature-id-range 1-5
The default is 0 to 255.
Set the attacker address range:
sensor(config-rul-fil)# attacker-address-range 10.89.10.10-10.89.10.23
The default is 0.0.0.0 to 255.255.255.255.
6-5.
Bad source and destination
Chapter 6
Configuring Event Action Rules
error.
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents