When To Disable Anomaly Detection; Troubleshooting Global Correlation - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

When to Disable Anomaly Detection

CISCO-PROCESS-MIB is available on the sensor, but we do not support it. We know that some elements
Note
are not available. While you can use elements from CISCO-PROCESS-MIB, we do not guarantee that
they all provide correct information. We fully support the other listed MIBs and their output is correct.
When to Disable Anomaly Detection
If you have your sensor configured to see only one direction of traffic, you should disable anomaly
detection. Otherwise, you will receive many alerts, because anomaly detection sees asymmetric traffic
as having incomplete connections, that is, like worm scanners, and fires alerts.
To disable anomaly detection, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Enter analysis engine submode.
Step 2
sensor# configure terminal
sensor(config)# service analysis-engine
sensor(config-ana)#
Enter the virtual sensor name that contains the anomaly detection policy you want to disable.
Step 3
sensor(config-ana)# virtual-sensor vs0
sensor(config-ana-vir)#
Disable anomaly detection operational mode.
Step 4
sensor(config-ana-vir)# anomaly-detection
sensor(config-ana-vir-ano)# operational-mode inactive
sensor(config-ana-vir-ano)#
Step 5
Exit analysis engine submode.
sensor(config-ana-vir-ano)# exit
sensor(config-ana-vir)# exit
sensor(config-ana-)# exit
Apply Changes:?[yes]:
Press Enter to apply your changes or enter
Step 6
For More Information
For more information about Worms, refer to Worms.

Troubleshooting Global Correlation

Make sure you observe the following when configuring global correlation:
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
A-20
Because global correlation updates occur through the sensor management interface, firewalls must
allow port 443/80 traffic.
You must have an HTTP proxy server or a DNS server configured to allow global correlation
features to function.
to discard them.
no
Chapter A
Troubleshooting
OL-18504-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents