Configuring Tcp Stream Reassembly; Overview; Configuring Tcp Stream Reassembly Parameters; Configuring The Mode For Tcp Stream Reassembly - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring Signatures
To configure IP fragment reassembly, follow these steps:
Log in to the CLI using an account with administrator or operator privileges.
Step 1
Enter fragment reassembly submode:
Step 2
sensor# configure terminal
sensor(config)# service signature-definition sig0
sensor(config-sig)# fragment-reassembly
Configure the operating system you want the sensor to use to reassemble IP fragments:
Step 3
sensor(config-sig-fra)# ip-reassemble-mode linux
Step 4
Verify the setting:
sensor(config-sig-fra)# show settings
fragment-reassembly
-----------------------------------------------
-----------------------------------------------
sensor(config-sig-fra)#
Exit signature-definition submode:
Step 5
sensor(config-sig-fra)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 6

Configuring TCP Stream Reassembly

This section describes TCP stream reassembly, and contains the following topics:

Overview

You can configure the sensor to monitor only TCP sessions that have been established by a complete
three-way handshake. You can also configure how long to wait for the handshake to complete, and how
long to keep monitoring a connection where no more packets have been seen. The goal is to prevent the
sensor from creating alerts where a valid TCP session has not been established. There are known attacks
against sensors that try to get the sensor to generate alerts by simply replaying pieces of an attack. The
TCP session reassembly feature helps to mitigate these types of attacks against the sensor.
You configure TCP stream reassembly parameters per signature. You can configure the mode for TCP
stream reassembly.

Configuring TCP Stream Reassembly Parameters

Table 7-5
stream reassembly. The TCP stream reassembly signatures are part of the NORMALIZER engine.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
7-24
ip-reassemble-mode: linux default: nt
Overview, page 7-24
Configuring TCP Stream Reassembly Parameters, page 7-24
Configuring the Mode for TCP Stream Reassembly, page 7-27
lists TCP stream reassembly signatures with the parameters that you can configure for TCP
to discard them.
no
Chapter 7
Defining Signatures
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents