Deny Attackers; Configuring The General Settings - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

General Settings

Deny Attackers

You can configure certain aspects of the deny attackers inline event action. You can configure the number
of seconds you want to deny attackers inline and you can limit the number of attackers you want denied
in the system at any one time.

Configuring the General Settings

Use the following commands in service event action rules submode to configure general event action
rules settings:
To configure event action general settings, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Enter event action rules submode:
Step 2
sensor# configure terminal
sensor(config)# service event-action-rules rules0
Enter general submode:
Step 3
sensor(config)# general
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
6-16
Global Summarization—Global Summarization mode fires an alert for every summary interval.
Signatures can be preconfigured for global summarization.
Fire Once—Fire Once mode fires an alert for each address set. You can upgrade this mode to Global
Summarization mode.
global-block-timeout —Number of minutes to block a host or connection.
The valid range is 0 to 10000000. The default is 30 minutes.
global-deny-timeout—Number of seconds to deny attackers inline.
The valid range is 0 to 518400. The default is 3600.
global-filters-status [enabled | disabled]—Enables or disables the use of the filters.
The default is enabled.
global-metaevent-status [enabled | disabled]—Enables or disables the use of the Meta Event
Generator.
The default is enabled.
global-overrides-status [enabled | disabled]—Enables or disables the use of the overrides.
The default is enabled.
global-summarization-status [enabled | disabled]—Enables or disables the use of the
summarizer.
The default is enabled.
max-denied-attackers—Limits the number of denied attackers possible in the system at any one
time.
The valid range is 0 to 100000000. The default is 10000.
Chapter 6
Configuring Event Action Rules
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents