Chapter 10
Configuring the Sensor Using the CLI
SERVICE.SMB
SERVICE.SMTP
SERVICE.SNMP
SERVICE.SSH
SERVICE.SYSLOG
show
ShunEvent
STATE.STRING.CISCOLOGIN
STATE.STRING.LPRFORMATSTRING
StreamReassembly
STRING.ICMP
STRING.TCP
STRING.UDP
SWEEP.HOST.ICMP
SWEEP.HOST.TCP
SWEEP.MULTI
SWEEP.OTHER.TCP
SWEEP.PORT.TCP
SWEEP.PORT.UDP
systemVariables
TRAFFIC.ICMP
TROJAN.BO2K
TROJAN.TFN2K
TROJAN.UDP
Step 6
Step 7
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
SMB Service decode inspection.
SMTP Protocol Inspection Engine
Inspects SNMP traffic
SSH header decode signatures.
Engine to process syslogs,
Display system settings and/or history
information
Shun Event configuration tokens
Telnet based Cisco Login Inspection
Engine
LPR Protocol Inspection Engine
Stream Reassembly configuration tokens
Generic ICMP based string search Engine
Generic TCP based string search Engine.
Generic UDP based string search Engine
ICMP host sweeps from a single attacker
to many victims.
TCP-based Host Sweeps from a single
attacker to multiple victims.
UDP and TCP combined port sweeps.
Odd sweeps/scans such as nmap
fingerprint scans.
Detects port sweeps between two nodes.
Detects UDP connections to multiple
destination ports between two nodes.
User modifiable system variables
Identifies ICMP traffic irregularities.
BackOrifice BO2K trojan traffic
TFN2K trojan/ddos traffic
Detects BO/BO2K UDP trojan traffic.
Type the name of engine you want to see.
For example, to see the settings for the engine that inspects the Network Time
Protocol (NTP):
sensor(config-vsc-virtualSensor)# service.ntp
The prompt changes to indicate which signature engine you are in. In the example
above, the prompt would be:
View the parameters for that specific signature engine:
sensor(config-vsc-virtualSensor-SER)# show settings
SERVICE.NTP
-----------------------------------------------
version: 4.0 <protected>
signatures (min: 0, max: 1000, current: 1)
-----------------------------------------------
sensor(config-vsc-virtualSensor-SER)#
Sensor Configuration Tasks
.
10-41
Need help?
Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?
Questions and answers