Configuring Addresses Never To Block - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 10
Configuring Blocking
Verify the number of maximum interfaces:
Step 5
sensor(config-net-gen)# show settings
general
-----------------------------------------------
Return the setting to the default of 250:
Step 6
sensor(config-net-gen)# default max-interfaces
Verify the default setting:
Step 7
sensor(config-net-gen)# show settings
general
-----------------------------------------------
Exit network access mode:
Step 8
sensor(config-net-gen)# exit
sensor(config-net)# exit
Apply Changes:?[yes]:
Step 9
Press Enter to apply the changes or type

Configuring Addresses Never to Block

Use the never-block-hosts and the never-block-networks commands in the service network access
submode to configure hosts and network that should never be blocked.
The following options apply:
You must tune your sensor to identify hosts and networks that should never be blocked, not even
manually, because you may have a trusted network device whose normal, expected behavior appears to
be an attack. Such a device should never be blocked, and trusted, internal networks should never be
blocked.
78-16527-01
log-all-block-events-and-errors: true default: true
enable-nvram-write: false default: false
enable-acl-logging: false default: false
allow-sensor-block: false <defaulted>
block-enable: true <defaulted>
block-max-entries: 250 <defaulted>
max-interfaces: 50 default: 250
master-blocking-sensors (min: 0, max: 100, current: 0)
-----------------------------------------------
log-all-block-events-and-errors: true default: true
enable-nvram-write: false default: false
enable-acl-logging: false default: false
allow-sensor-block: false <defaulted>
block-enable: true <defaulted>
block-max-entries: 250 <defaulted>
max-interfaces: 250 <defaulted>
master-blocking-sensors (min: 0, max: 100, current: 0)
----------------------------------------------
ip_address—IP address of the device that should never be blocked.
ip_address
netmask— IP address of the network that should never be blocked. The format for is
/
A.B.C.D./nn.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Configuring Blocking Properties
10-15

Advertisement

Table of Contents
loading

Table of Contents