Enterasys Intrusion Prevention System Manual page 105

Network sensor policies and signatures guide
Hide thumbs Also See for Intrusion Prevention System:
Table of Contents

Advertisement

4.
Expand RPC Analysis in the Protocol column.
5.
RPC analysis is enabled by default. To disable it, click disable in the Property column, then
select yes from the drop-down list in the Value column.
6.
The any-port property is disabled by default. To cause the Network Sensor to attempt an RPC
decode of every packet it sees, regardless of destination port, click any-port in the Property
column, then select yes from the drop-down list in the Value column.
7.
By default, only inbound traffic to the protected network is monitored. To enable RPC
monitoring of all traffic, disable the inbound-only property. Click inbound-only in the
Property column, then select no from the drop-down list in the Value column.
8.
The port macro "R" is configured by default. This macro specifies port 111 and the port range
from 32768 to 32900. To add or exclude a port or port range for analysis, click Add Port. The
Add Port Information dialog box is displayed.
Configuring the Protocol Analysis Module
Creating Network Sensor Policies and Signatures 2-75

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Intrusion Prevention System and is the answer not in the manual?

Table of Contents