Event Actions - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix B
Signature Engines
Table B-2
Parameter
alert-frequency
summary-mode
fire-all
fire-once
global-summarize
summarize
specify-summary-threshold
summary-threshold
specify-global-summary-threshold Enable global summary threshold.
global-summary-threshold
summary-interval
summary-key

Event Actions

The following event action parameters belong to each signature engine:
78-16527-01
MASTER Engine Alert Frequency Parameters
produce-alert—Writes an <evIdsAlert> to the Event Store.
produce-verbose-alert—Includes an encoded dump (possibly truncated) of the offending packet in
the evIdsAlert.
deny-attacker-inline —Does not transmit this packet and future packets from the attacker address
for a specified period of time (inline only).
This is the most severe of the deny actions. It denies the current and future packets from a
Note
single attacker address. Each deny address times out for X seconds from the first event that
caused the deny to start, where X is the amount of seconds that you configured global-
deny-timeout in Event Action Rules. You can clear all denied attacker entries with the clear
denied-attackers command, which permits the addresses back on the network.
deny-connection-inline —Does not transmit this packet and future packets on the TCP Flow (inline
only).
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Description
Summary options for grouping alerts.
Mode used for summarization.
Fires an alert on all events.
Fires an alert only once.
Summarizes an alert so that it only fires once
regardless of how many attackers or victims.
Summarizes alerts.
(Optional) Enables summary threshold.
Threshold number of alerts to send signature into
summary mode.
Threshold number of events to take alerts into global
summary.
Time in seconds used in each summary alert.
The storage type on which to summarize this
signature:
Attacker address
Attacker and victim addresses
Attacker address and victim port
Victim address
Attacker and victim addresses and ports
MASTER Engine
Value
yes | no
0 to 65535
yes | no
1 to 65535
1 to 1000
Axxx
AxBx
Axxb
xxBx
AaBb
B-5

Advertisement

Table of Contents
loading

Table of Contents