Enterasys Intrusion Prevention System Manual page 198

Network sensor policies and signatures guide
Hide thumbs Also See for Intrusion Prevention System:
Table of Contents

Advertisement

6.x to 7.x Mappings
Table A-1 6.x to 7.0 Keyword Mapping (continued)
6.x Keyword
CUSHION
DAEMON
DEBUG
A-4 Keywords/XML Attributes
7.0 XML Attribute
NSC/SC/C/Dynamic/cushion
NSC/daemonize
NSC/debug
Description
The basic format for the complex rule is the rule's
unique character (such as W for web rules or X
for X Windows rules), the rule type (from the
previous table) and any required arguments. The
characters W and R are reserved letters. W is
used to only assign port ranges that should have
the HTTP protocol associated with them. R
specifies RPC ports.
Additional amounts of Dynamic packet logging
can be set for all events. This attribute specifies
how many packets for Network Sensor to collect
in addition to the normal number of packets
specified by a signature in the dragon.sigs file.
For example, if a PHF attack signature has a
Dynamic packet capture level of 10 packets and
the value is set to 5 packets, the Network Sensor
will attempt to collect 15 packets. This rule is
meant as an easy way to quickly turn up the
sensitivity of a Network Sensor. The extra
logging may have a negative impact on system
performance or on Network Sensor hard drive
space.
Makes the Enterasys IPS Sensor run as a
background process. This mode does not allow
any printing to standard output. This is the most
common way to run the Enterasys IPS Sensor.
When in Daemonize mode, the Enterasys IPS
Sensor will write out its process ID to a file called
dragon.pid that is useful for utility and
maintenance scripts. Daemonize mode is always
enabled with dragon.net configuration files from
the Enterasys IPS Server.
This causes the Enterasys IPS Sensor to print
out all of the variables from 'dragon.net' and
'dragon.sigs' as they are loaded when it is first
started. It is useful for diagnosing incorrect
configuration file errors. This setting will not work
when the Enterasys IPS Sensor is run as a
background process. This setting is not available
through the Enterasys IPS Server management
interface and is reserved for diagnostics and
troubleshooting.
Technical Note
Placing the debug at the top of the dragon.net
file ensures that debugging information will be
provided for each keyword.

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Intrusion Prevention System and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents