Blocking Not Occurring For A Signature - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Troubleshooting the Appliance
Enable SSH:
Step 3
sensor(config)# ssh host blocking_device_ip_address
Type
Step 4

Blocking Not Occurring for a Signature

If blocking is not occurring for a specific signature, check that the event action is set to block the host.
To make sure blocking is occurring for a specific signature, follow these steps:
Log in to the CLI.
Step 1
Enter signature definition submode.
Step 2
sensor# configure terminal
sensor(config)# service signature-definition sig0
sensor(config-sig)#
Make sure the event action is set to block the host.
Step 3
Note
sensor(config-sig)# signatures 1300 0
sensor(config-sig-sig)# engine normalizer
sensor(config-sig-sig-nor)# event-action produce-alert|request-block-host
sensor(config-sig-sig-nor)# show settings
normalizer
-----------------------------------------------
-connection-inline
--MORE--
Exit signature definition submode.
Step 4
sensor(config-sig-sig-nor)# exit
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
A-44
when prompted to accept the device.
yes
If you want to receive alerts, you must always add produce-alert any time you configure the
event actions.
event-action: produce-alert|request-block-host default: produce-alert|deny
edit-default-sigs-only
-----------------------------------------------
default-signatures-only
-----------------------------------------------
specify-service-ports
-----------------------------------------------
no
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
specify-tcp-max-mss
-----------------------------------------------
no
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
specify-tcp-min-mss
-----------------------------------------------
no
-----------------------------------------------
-----------------------------------------------
Chapter A
Troubleshooting
OL-18504-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents