Clearing The Denied Attackers List - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

General Settings

Clearing the Denied Attackers List

Use the clear denied-attackers command in service event action rules submode to delete the denied
attackers list and clear the virtual sensor statistics.
If your sensor is configured to operate in inline mode, the traffic is passing through the sensor. You can
configure signatures to deny packets, connections, and attackers while in inline mode, which means that
single packets, connections, and specific attackers will be denied, that is, not transmitted, when the
sensor encounters them.
When the signature fires, the attacker is denied and placed in a list. As part of sensor administration, you
may want to delete the list or clear the statistics in the list.
To delete the list of denied attackers and clear the statistics, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Step 2
Display the list of denied IP addresses:
sensor# show statistics denied-attackers
Denied Attackers and hit count for each.
10.20.4.2 = 9
10.20.5.2 = 5
The statistics show that there are two IP addresses being denied at this time.
Delete the denied attackers list:
Step 3
sensor# clear denied-attackers
Warning: Executing this command will delete all addresses from the list of
attackers currently being denied by the sensor.
Continue with clear? [yes]:
Type
Step 4
Verify that you have cleared the list:
Step 5
sensor# show statistics virtual-sensor
Virtual Sensor Statistics
Statistics for Virtual Sensor vs0
There is no longer any information under the
To clear only the statistics:
Step 6
sensor# show statistics virtual-sensor clear
Step 7
Verify that you have cleared the statistics:
JWK-4255# show statistics virtual-sensor
Virtual Sensor Statistics
Statistics for Virtual Sensor vs0
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
6-18
to clear the list.
yes
Name of current Signature-Definition instance = sig0
Name of current Event-Action-Rules instance = rules0
List of interfaces monitored by this virtual sensor = mypair
Denied Address Information
Number of Active Denied Attackers = 0
Number of Denied Attackers Inserted = 2
Number of Denied Attackers Total Hits = 287
Number of times max-denied-attackers limited creation of new entry = 0
Number of exec Clear commands during uptime = 1
Denied Attackers and hit count for each.
Name of current Signature-Definition instance = sig0
Name of current Event-Action-Rules instance = rules0
Chapter 6
Denied Attackers and hit count for each category
Configuring Event Action Rules
.
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents