Service.rpc Engine - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix B
Signature Engines
You can tune this signature and create custom signatures based on NTP protocol values, such as mode
and size of control packets.
Table B-19
Table B-19
Parameter
inspection-type
inspect-ntp-packets
is-invalid-data-packet
is-non-ntp-traffic

SERVICE.RPC Engine

The SERVICE.RPC engine specializes in RPC protocol and has full decode as an anti-evasive strategy.
It can handle fragmented messages (one message in several packets) and batch messages (several
messages in a single packet).
The RPC portmapper operates on port 111. Regular RPC messages can be on any port greater than 550.
RPC sweeps are like TCP port sweeps, except that they only count unique ports when a valid RPC
message is sent. RPC also runs on UDP.
Table B-20
Table B-20
Parameter
direction
protocol
service-ports
specify-is-spoof-src
78-16527-01
lists the parameters specific to the SERVICE.NTP engine.
SERVICE.NTP Engine Parameters
Description
Type of inspection to perform.
Inspects NTP packets:
control-opcode—Opcode number of an NTP control
packet according to RFC1305, Appendix B.
max-control-data-size—Maximum allowed amount of
data sent in a control packet.
mode —Mode of operation of the NTP packet per RFC
1305.
Looks for invalid NTP data packets. Checks the structure of
the NTP data packet to make sure it is the correct size.
Checks for nonNTP packets on an NTP port.
lists the parameters specific to the SERVICE.RPC engine.
SERVICE.RPC Engine Parameters
Description
Direction of traffic:
Traffic from service port destined to client port.
Traffic from client port destined to service port.
Protocol of interest.
A comma-separated list of ports or port ranges where
the target service resides.
(Optional) Enables the spoof source address:
is-spoof-src—Fires an alert when the source
address is 127.0.0.1.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
SERVICE Engines
Value
0 to 65535
true | false
true | false
Value
from-service
to-service
tcp
udp
1
0 to 65535
a-b[,c-d]
true | false
B-23

Advertisement

Table of Contents
loading

Table of Contents