Service.msrpc Engine; Overview; Service.msrpc Engine Parameters - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix B
Signature Engines
Table B-16
Table B-16
Parameter
inspection-type
has-bad-port
has-newline
size
service-ports
direction
1. The second number in the range must be greater than or equal to the first number.

SERVICE.MSRPC Engine

This section describes the SERVICE.MSRPC engine, and contains the following topics:

Overview

The SERVICE.MSRPC engine processes MSRPC packets. MSRPC allows for cooperative processing
between multiple computers and their application software in a networked environment. It is a
transaction-based protocol, implying that there is a sequence of communications that establish the
channel and pass processing requests and replies.
MS RPC is an ISO layer 5-6 protocol and is layered on top of other transport protocols such as UDP,
TCP, and SMB. The MSRPC engine contains facilities to allow for fragmentation and reassembly of the
MSRPC PDUs.
This communication channel is the source of recent Windows NT, Windows 2000, and Window XP
security vulnerabilities.
The SERVICE.MSRPC engine only decodes the DCE and RPC protocol for the most common
transaction types.

SERVICE.MSRPC Engine Parameters

Table B-17 on page B-22
78-16527-01
lists the parameters specific to the SERVICE.IDENT engine.
SERVICE.IDENT Engine Parameters
Description
Type of inspection to perform.
Inspects payload for a bad port.
Inspects payload for a nonterminating new line character.
Inspects for payload length longer than this.
A comma-separated list of ports or port ranges where the target
service resides.
Direction of the traffic:
Traffic from service port destined to client port.
Traffic from client port destined to service port.
Overview, page B-21
SERVICE.MSRPC Engine Parameters, page B-21
lists the parameters specific to the SERVICE.MSRPC engine.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
SERVICE Engines
Value
true | false
true | false
0 to 65535
1
0 to 65535
a-b[,c-d]
from-service
to-service
B-21

Advertisement

Table of Contents
loading

Table of Contents