Configuring Aic Signatures; Overview - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring Signatures
Configure the event action:
Step 5
sensor(config-sig-sig-nor)# event-action produce-alert|request-snmp-trap
Note
Verify the settings:
Step 6
sensor(config-sig-sig-nor)# show settings
normalizer
-----------------------------------------------
produce-alert|deny-packet-inline
Step 7
Exit event action submode:
sensor(config-sig-sig-nor)# exit
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 8

Configuring AIC Signatures

This section describes the AIC signatures and how to configure them. It contains the following topics:

Overview

AIC provides deep analysis of web traffic. It provides granular control over HTTP sessions to prevent
abuse of the HTTP protocol. It also allows administrative control over applications that attempt to tunnel
over specified ports, such as instant messaging, and tunneling applications such as, gotomypc.
Inspection and policy checks for P2P and instant messaging is possible if these applications are running
over HTTP.
AIC also provides a way to inspect FTP traffic and control the commands being issued.
You can enable or disable the predefined signatures or you can create policies through custom
signatures.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
7-12
Each time you configure the event actions for a signature, you overwrite the previous
configuration. For example, if you always want to produce an alert when the signature is fired,
you must configure it along with the other event actions you want. Use the | symbol to add more
than one event action, for example, product-alert|deny-packet-inline|request-snmp-trap.
event-action: produce-alert|request-snmp-trap default:
Overview, page 7-12
Configuring the Application Policy, page 7-13
AIC Request Method Signatures, page 7-15
AIC MIME Define Content Type Signatures, page 7-16
AIC Transfer Encoding Signatures, page 7-19
AIC FTP Commands Signatures, page 7-20
to discard them.
no
Chapter 7
Defining Signatures
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents