General Settings
•
•
Deny Attackers
You can configure certain aspects of the deny attackers inline event action. You can configure the number
of seconds you want to deny attackers inline and you can limit the number of attackers you want denied
in the system at any one time.
Configuring the General Settings
Use the following commands in service event action rules submode to configure general event action
rules settings:
•
•
•
•
•
•
•
To configure event action general settings, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Enter event action rules submode:
Step 2
sensor# configure terminal
sensor(config)# service event-action-rules rules0
Enter general submode:
Step 3
sensor(config)# general
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
6-16
Global Summarization—Global Summarization mode fires an alert for every summary interval.
Signatures can be preconfigured for global summarization.
Fire Once—Fire Once mode fires an alert for each address set. You can upgrade this mode to Global
Summarization mode.
global-block-timeout —Number of minutes to block a host or connection.
The valid range is 0 to 10000000. The default is 30 minutes.
global-deny-timeout—Number of seconds to deny attackers inline.
The valid range is 0 to 518400. The default is 3600.
global-filters-status [enabled | disabled]—Enables or disables the use of the filters.
The default is enabled.
global-metaevent-status [enabled | disabled]—Enables or disables the use of the Meta Event
Generator.
The default is enabled.
global-overrides-status [enabled | disabled]—Enables or disables the use of the overrides.
The default is enabled.
global-summarization-status [enabled | disabled]—Enables or disables the use of the
summarizer.
The default is enabled.
max-denied-attackers—Limits the number of denied attackers possible in the system at any one
time.
The valid range is 0 to 100000000. The default is 10000.
Chapter 6
Configuring Event Action Rules
78-16527-01
Need help?
Do you have a question about the 4215 - Intrusion Detection Sys Sensor and is the answer not in the manual?
Questions and answers