Cisco IPS 7.1 Installation Manual page 257

Intrusion prevention system appliance and module
Table of Contents

Advertisement

Appendix B
Initializing the Sensor
Step 16
Enter
Signature Definition Configuration
[1] sig0
[2] Create a new signature definition configuration
Option[2]:
Enter
Step 17
Enter the signature-definition configuration name,
Step 18
Event Action Rules Configuration
[1] rules0
[2] Create a new event action rules configuration
Option[2]:
Enter
Step 19
Note
Virtual Sensor: newVs
Anomaly Detection: ad0
Event Action Rules: rules0
Signature Definitions: newSig
Monitored:
PortChannel0/0
[1] Remove virtual sensor.
[2] Modify "newVs" virtual sensor configuration.
[3] Modify "vs0" virtual sensor configuration.
[4] Create new virtual sensor.
Option:
Press Enter to exit the interface and virtual sensor configuration menu.
Step 20
Modify default threat prevention settings?[no]:
Enter
Step 21
Note
Virtual sensor newVs is configured to prevent high risk threats in inline mode. (Risk
Rating 90-100)
Virtual sensor vs0 is configured to prevent high risk threats in inline mode.(Risk Rating
90-100)
Do you want to disable automatic threat prevention on all virtual sensors?[no]:
Enter
Step 22
The following configuration was entered.
service host
network-settings
host-ip 192.168.1.2/24,192.168.1.1
host-name asa-ips
telnet-option disabled
sshv1-fallback enabled
access-list 10.0.0.0/8
access-list 64.0.0.0/8
OL-24002-01
to use the existing anomaly-detection configuration, ad0.
1
to create a signature-definition configuration file.
2
to use the existing event-action-rules configuration, rules0.
1
If PortChannel 0/0 has not been assigned to vs0, you are prompted to assign it to the new virtual
sensor.
if you want to modify the default threat prevention settings.
yes
The sensor comes with a built-in override to add the deny packet event action to high risk rating
alerts. If you do not want this protection, disable automatic threat prevention.
to disable automatic threat prevention on all virtual sensors.
yes
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.1
.
newSig
Advanced Setup
B-19

Advertisement

Table of Contents
loading

Table of Contents