Advanced Setup
Description[Created via setup by user cisco]: New Sensor
Anomaly Detection Configuration
[1] ad0
[2] Create a new anomaly detection configuration
Option[2]:
Enter
Step 15
Signature Definition Configuration
[1] sig0
[2] Create a new signature definition configuration
Option[2]:
Step 16
Enter
Step 17
Enter the signature-definition configuration name,
Event Action Rules Configuration
[1] rules0
[2] Create a new event action rules configuration
Option[2]:
Enter
Step 18
Note
Note
Note
Virtual Sensor: newVs
Anomaly Detection: ad0
Event Action Rules: rules0
Signature Definitions: newSig
Monitored:
GigabitEthernet0/1
[1] Remove virtual sensor.
[2] Modify "newVs" virtual sensor configuration.
[3] Modify "vs0" virtual sensor configuration.
[4] Create new virtual sensor.
Option:
Step 19
Press Enter to exit the interface and virtual sensor configuration menu.
Modify default threat prevention settings?[no]:
Enter
Step 20
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
10-18
to use the existing anomaly-detection configuration, ad0.
1
to create a signature-definition configuration file.
2
to use the existing event-action-rules configuration, rules0.
1
If GigabitEthernet0/1 has not been assigned to vs0, you are prompted to assign it to the new
virtual sensor.
With ASA 7.2 and earlier, one virtual sensor is supported. The virtual sensor to which
GigabitEthernet0/1 is assigned is used for monitoring packets coming from the adaptive security
appliance. We recommend that you assign GigabitEthernet0/1 to vs0, but you can assign it to
another virtual sensor if you want to.
With ASA 7.2.3 and later with IPS 6.0, multiple virtual sensors are supported. The ASA 7.2.3
can direct packets to specific virtual sensors or can send packets to be monitored by a default
virtual sensor. The default virtual sensor is the virtual sensor to which you assign
GigabitEthernet0/1. We recommend that you assign GigabitEthernet0/1 to vs0, but you can
assign it to another virtual sensor if you want to.
if you want to modify the default threat prevention settings.
yes
Chapter 10
.
newSig
Initializing the Sensor
OL-18504-01
Need help?
Do you have a question about the IPS-4255-K9 - Intrusion Protection Sys 4255 and is the answer not in the manual?