Configuring Alert Severity - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring Signatures
Configure the alert frequency of this signature:
Step 5
a.
b.
c.
Exit alert-frequency submode:
Step 6
sensor(config-sig-sig-ale-fir)# exit
sensor(config-sig-sig-ale)# exit
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 7

Configuring Alert Severity

Use the alert-severity command in the signature definition submode to configure the severity of a
signature.
The following options apply:
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
7-6
Configure the summary mode to, for example, fire once:
sensor(config-sig-sig-ale)# summary-mode fire-once
sensor(config-sig-sig-ale-fir)# specify-global-summary-threshold yes
sensor(config-sig-sig-ale-fir-yes)# global-summary-threshold 3000
sensor(config-sig-sig-ale-fir-yes)# summary-interval 5000
Configure the summary key:
sensor(config-sig-sig-ale-fir-yes)# exit
sensor(config-sig-sig-ale-fir)# summary-key AxBx
Verify the settings:
sensor(config-sig-sig-ale-fir)# show settings
fire-once
-----------------------------------------------
summary-key: AxBx default: Axxx
specify-global-summary-threshold
-----------------------------------------------
yes
-----------------------------------------------
global-summary-threshold: 3000 default: 120
summary-interval: 5000 default: 15
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
sensor(config-sig-sig-ale-fir)#
sig-id—Identifies the unique numerical value assigned to this signature.
This value lets the sensor identify a particular signature. The value is 1000 to 65000.
subsig-id—Identifies the unique numerical value assigned to this subsignature.
A subsignature ID is used to identify a more granular version of a broad signature. The value is 0 to
255.
alert-severity—Severity of the alert:
high —Dangerous alert.
medium—Medium level alert.
to discard them.
no
Chapter 7
Defining Signatures
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents