Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual page 245

Intrusion detection system appliance and module
Table of Contents

Advertisement

Chapter 10
Configuring the Sensor Using the CLI
FlipAddr
MaxInspectLength
MaxTTL
MinHits
MinUDPLength
Protocol
ResetAfterIdle
ShortUDPLength
show
SigComment
SigStringInfo
SigVersion
SrcIpAddr
SrcIpMask
SrcPort
StorageKey
SummaryKey
ThrottleInterval
WantFrag
Type the name of the parameter that you want to configure and add or change the
Step 9
values.
For example, to change the destination port for signature ID 9019 from the default
2140 to 2139, type the following command:
sensor(config-vsc-virtualSensor-ATO-sig)# dstport 2139
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
True if address (and ports) Source and
Destination are swapped in the alarm message.
False for no swap (normal).
Maximum number of bytes to inspect.
Maximum number of seconds to inspect a
logical stream. The inspector is deleted after X
seconds of being active.
Minimum number of signature hits before the
alarm message is sent. This a limiter for
firing the alarm only after X times of seeing
the signature on the address key.
Fire alarm when packet UDP LENGTH is less
than this.
Protocol of interest for this inspector.
Number of seconds to wait to reset signature
counters after the host(s) were idle.
Fire alarm when IP Data length is less than
UDP Header Length
Display system settings and/or history
information
USER NOTES - miscellaneous information about
this signature
Extra information included in the alarm message.
Signature update version of signature
IP address (or network) to match on the IP
packet's source address. Must be used with
SrcIpMask.
IP netmask used with SrcIpAddr to match on
the IP packet's destination address. Must be
used with SrcIpAddr.
A single Source Port to match.
Type of Address Key used to store persistent
data.
The Storage Type on which to summarize this
signature.
Number of seconds defining an Alarm Throttle
interval. This is used with the AlarmThrottle
parameter to tune special alarm limiters.
True if a fragment is desired. False if a
fragment is not desired. Any for either.
Sensor Configuration Tasks
10-49

Advertisement

Table of Contents
loading

Table of Contents