Configuring The Status Of Signatures - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring Signatures
Exit signatures submode:
Step 6
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Step 7
Press Enter to apply the changes or type

Configuring the Status of Signatures

Use the status command in the signature definition submode to specify the status of a specific signature.
The following options apply:
Caution
Activating and retiring signatures can take 30 minutes or longer.
To change the status of a signature, follow these steps:
Log in to the CLI using an account with administrator or operator privileges.
Step 1
Enter signature definition submode:
Step 2
sensor# configure terminal
sensor(config)# service signature-definition sig0
Choose the signature you want to configure:
Step 3
sensor(config-sig)# signatures 12000 0
Change the status for this signature:
Step 4
sensor(config-sig-sig)# status
sensor(config-sig-sig-sta)# enabled true
Step 5
Verify the settings:
sensor(config-sig-sig-sta)# show settings
status
-----------------------------------------------
-----------------------------------------------
sensor(config-sig-sig-sta)#
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
7-10
sig-name: Gator Spyware Beacon <defaulted>
sig-string-info: /download/ User-Agent: Gator <defaulted>
sig-comment: <defaulted>
alert-traits: 0 <defaulted>
release: 71 <defaulted>
-----------------------------------------------
status—Identifies whether the signature is enabled, disabled, or retired.
enabled [true | false]—Enables the signature.
retired [true | false]—Retires the signature.
enabled: true default: false
retired: false <defaulted>
to discard them.
no
Chapter 7
Defining Signatures
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents