Assigning Actions To Signatures - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 7
Defining Signatures
Exit signatures submode:
Step 6
sensor(config-sig-sig-sta)# exit
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 7

Assigning Actions to Signatures

Use the event-action command in the signature definition submode to configure the actions the sensor
will take when the signature fires.
The following options apply:
To configure event actions for a signature, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Step 2
Enter signature definition mode:
sensor# configure terminal
sensor(config)# service signature-definition sig0
Choose the signature you want to configure:
Step 3
sensor(config-sig)# signatures 1200 0
Enter the normalizer engine:
Step 4
sensor(config-sig-sig)# engine normalizer
78-16527-01
produce-alert—Writes an evIdsAlert to the Event Store.
produce-verbose-alert—Includes an encoded dump (possibly truncated) of the offending packet in
the evIdsAlert.
deny-attacker-inline —Does not transmit this packet and future packets from the attacker address
for a specified period of time (inline only).
deny-connection-inline —Does not transmit this packet and future packets on the TCP Flow (inline
only).
deny-packet-inline—Does not transmit this packet.
log-attacker-packets—Starts IP logging of packets containing the attacker address (inline only).
log-pair-packets—Starts IP logging of packets containing the attacker-victim address pair.
log-victim-packets—Starts IP logging of packets containing the victim address.
request-block-connection—Requests Network Access Controller to block this connection.
request-block-host—Requests Network Access Controller to block this attacker host.
request-snmp-trap—Sends request to Notification App to perform SNMP action.
reset-tcp-connection—Sends TCP resets to hijack and terminate the TCP flow.
modify-packet-inline—Modifies packet contents (inline only).
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Configuring Signatures
7-11

Advertisement

Table of Contents
loading

Table of Contents