Changing Web Server Settings - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 4
Initial Configuration Tasks
-----------------------------------------------
sensor(config-hos-net)#
To remove the login banner text, use the no form of the command:
Step 5
sensor(config-hos-net)# no login-banner-text
Verify the login text has been removed:
Step 6
sensor(config-hos-net)# show settings
network-settings
-----------------------------------------------
-----------------------------------------------
sensor(config-hos-net)#
Exit network settings mode:
Step 7
sensor(config-hos-net)# exit
sensor(config-hos)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 8

Changing Web Server Settings

After you run the setup command, you can change the following web server settings: the web server port,
whether TLS encryption is being used, and the HTTP server header message.
The default web server port is 443 if TLS is enabled and 80 if TLS is disabled.
Note
HTTP is the protocol that web clients use to make requests from web servers. The HTTP specification
requires a server to identify itself in each response. Attackers sometimes exploit this protocol feature to
perform reconnaissance. If the IPS web server identified itself by providing a predictable response, an
attacker might learn that an IPS sensor is present.
We recommend that you not reveal to attackers that you have an IPS sensor. Change the server-id to
anything that does not reveal any information, especially if your web server is available to the Internet.
78-16527-01
access-list (min: 0, max: 512, current: 1)
-----------------------------------------------
network-address: 0.0.0.0/0
-----------------------------------------------
-----------------------------------------------
ftp-timeout: 300 seconds <defaulted>
login-banner-text: This is the banner login text message. default:
host-ip: 10.89.130.108/23,10.89.130.1
default: 10.1.9.201/24,10.1.9.1
host-name: sensor default: sensor
telnet-option: enabled default: disabled
access-list (min: 0, max: 512, current: 1)
-----------------------------------------------
network-address: 0.0.0.0/0
-----------------------------------------------
-----------------------------------------------
ftp-timeout: 300 seconds <defaulted>
login-banner-text: default:
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Changing Web Server Settings
4-9

Advertisement

Table of Contents
loading

Table of Contents