Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual page 242

Intrusion detection system appliance and module
Table of Contents

Advertisement

Sensor Configuration Tasks
Enter tune micro-engines submode:
Step 4
sensor(config-vsc)# tune-micro-engines
Type the name of the signature engine that you want to tune.
Step 5
Note
For example, to tune a simple UDP packet alarm, type the following command:
sensor(config-vsc-virtualSensor)# ATOMIC.UDP
View the signature settings:
Step 6
sensor(config-vsc-virtualSensor-ATO)# show settings
A summary of the signatures and settings is displayed.
sensor(config-vsc-virtualSensor-ATO)# show settings
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
10-46
You can view a list of all signature engines by typing a question mark (?)
at the
sensor(config-vsc-virtualSensor)#
ATOMIC.UDP
-----------------------------------------------
version: 4.0 <protected>
signatures (min: 0, max: 1000, current: 13)
-----------------------------------------------
SIGID: 9019 <protected>
SubSig: 0 <protected>
AlarmDelayTimer:
AlarmInterval:
AlarmSeverity: informational <defaulted>
AlarmThrottle: FireOnce <defaulted>
AlarmTraits:
CapturePacket: False <defaulted>
ChokeThreshold: 100 <defaulted>
DstIpAddr:
DstIpMask:
DstPort: 2140 <defaulted>
Enabled: False <defaulted>
EventAction:
FlipAddr:
MaxInspectLength:
MaxTTL:
MinHits:
MinUDPLength:
Protocol: UDP <defaulted>
ResetAfterIdle: 15 <defaulted>
ShortUDPLength:
Chapter 10
Configuring the Sensor Using the CLI
prompt.
78-15597-02

Advertisement

Table of Contents
loading

Table of Contents