Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual page 115

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 6
Configuring Event Action Rules
To enable or disable the meta event generator:
Step 4
sensor(config-rul-gen)# global-metaevent-status [enabled | disabled]
The default is enabled.
To enable or disable the summarizer:
Step 5
sensor(config-rul-gen)# global-summarization-status [enabled | disabled]
The default is enabled.
To configure the denied attackers inline event action:
Step 6
To limit the number of denied attackers in the system at any given time:
a.
sensor(config-rul-gen)# max-denied-attackers 100
The default is 1000.
To configure the amount of seconds to deny attackers in the system:
b.
sensor(config-rul-gen)# global-deny-timeout 1000
The default is 3600 seconds.
To configure the number of minutes to block a host or a connection:
Step 7
sensor(config-rul-gen)# global-block-timeout 20
The default is 30 minutes.
Step 8
To enable or disable any overrides that you have set up:
sensor(config-rul-gen)# global-overrides-status [enabled | disabled]
The default is enabled.
To enable or disable any filters that you have set up:
Step 9
sensor(config-rul-gen)# global-filters-status [enabled | disabled]
The default is enabled.
Check the settings for general submode:
Step 10
sensor(config-rul-gen)# show settings
general
-----------------------------------------------
-----------------------------------------------
sensor(config-rul-gen)#
Exit event action rules submode:
Step 11
sensor(config-rul-gen)# exit
sensor(config-rul)# exit
Apply Changes:?[yes]:
Press Enter to apply your changes or type
Step 12
78-16527-01
global-overrides-status: Enabled default: Enabled
global-filters-status: Enabled default: Enabled
global-summarization-status: Enabled default: Enabled
global-metaevent-status: Enabled default: Enabled
global-deny-timeout: 1000 default: 3600
global-block-timeout: 20 default: 30
max-denied-attackers: 100 default: 10000
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
General Settings
6-17

Advertisement

Table of Contents
loading

Table of Contents