Event Actions - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 6
Configuring Event Action Rules
Figure 6-1
signature, address, port, RR, etc.

Event Actions

Table 6-1
Table 6-1
Event Action Name
Produce Alert
Produce Verbose Alert
Deny Attacker Inline
Deny Connection Inline
Deny Packet Inline
78-16527-01
Signature Event Through SEAP
Signature event with
configured action
Signature event
Add action based on RR
Subtract action based on
Subtract action based on
current summary mode
Perform action
describes the event actions.
Event Actions
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Event count
Signature event
action override
Signature event
action filter
Signature event
summary filter
Signature event
action handler
Description
Writes the event to the Event Store as an evIdsAlert.
Includes an encoded dump of the offending packet in the evIdsAlert.
Does not transmit this packet and future packets originating from the
attacker address for a specified period of time (inline mode only).
Does not transmit this packet and future packets on the TCP flow
(inline mode only).
Does not transmit this packet (inline only).
Event Actions
Consumed
signature event
6-3

Advertisement

Table of Contents
loading

Table of Contents