Service Engines; Service.dns Engine - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix B
Signature Engines
Table B-10
Parameter
specify-max-fragments-per-dgram
specify-max-last-fragments
specify-max-partial-dgrams
specify-max-small-frags
specify-min-fragment-size
specify-service-ports
specify-syn-flood-max-embrionic
specify-tcp-closed-timeout
specify-tcp-embryonic-timeout
specify-tcp-idle-timeout
specify-tcp-max-mss
specify-tcp-max-queue
specify-tcp-min-mss
specify-tcp-option-number

SERVICE Engines

The SERVICE engines analyze L5+ traffic between two hosts. These are one-to-one signatures that track
persistent data. The engines analyze the L5+ payload in a manner similar to the live service.
The SERVICE engines have common characteristics but each engine has specific knowledge of the
service that it is inspecting. The SERVICE engines supplement the capabilities of the generic string
engine specializing in algorithms where using the string engine is inadequate or undesirable.
This section contains the following topics:
78-16527-01
NORMALIZER Engine Parameters (continued)
SERVICE.DNS Engine, page B-14
SERVICE.FTP Engine, page B-15
SERVICE.GENERIC Engine, page B-16
SERVICE.H225 Engine, page B-16
SERVICE.HTTP Engine, page B-19
SERVICE.IDENT Engine, page B-20
SERVICE.MSRPC Engine, page B-21
SERVICE.MSSQL Engine, page B-22
SERVICE.NTP Engine, page B-22
SERVICE.RPC Engine, page B-23
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Description
(Optional) Enables maximum fragments per datagram.
(Optional) Enables maximum last fragments.
(Optional) Enables maximum partial datagrams.
(Optional) Enables maximum small fragments.
(Optional) Enables minimum fragment size.
(Optional) Enables service ports.
(Optional) Enables SYN flood maximum embryonic.
(Optional) Enables TCP closed timeout.
(Optional) Enables TCP embryonic timeout.
(Optional) Enables TCP idle timeout.
(Optional) Enables TCP maximum mss.
(Optional) Enables TCP maximum queue.
(Optional) Enables TCP minimum mss.
(Optional) Enables TCP option number.
SERVICE Engines
B-13

Advertisement

Table of Contents
loading

Table of Contents