Service.ftp Engine - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix B
Signature Engines
Table B-11
Parameter
specify-query-src-port-53
specify-query-stream-len
specify-query-type
specify-query-value

SERVICE.FTP Engine

The SERVICE.FTP engine specializes in FTP PORT command decode, trapping invalid PORT
commands and the PASV port spoof. It fills in the gaps when the STRING engine is not appropriate for
detection. The parameters are Boolean and map to the various error trap conditions in the PORT
command decode. The SERVICE.FTP engine runs on TCP ports 20 and 21. Port 20 is for data and the
SERVICE.FTP engine does not do any inspection on this. It inspects the control transactions on port 21.
Table B-12
Table B-12
Parameter
direction
ftp-inspection-type
service-ports
swap-attacker-victim True if address (and ports) source and destination are
1. The second number in the range must be greater than or equal to the first number.
78-16527-01
SERVICE.DNS Engine Parameters (continued)
lists the parameters that are specific to the SERVICE.FTP engine.
SERVICE.FTP Engine Parameters
Description
Direction of traffic:
Traffic from service port destined to client port
Traffic from client port destined to service port
Type of inspection to perform:
Looks for an invalid address in the FTP port
command
Looks for an invalid port in the FTP port command
Looks for the PASV port spoof
A comma-separated list of ports or port ranges where
the target service resides.
swapped in the alert message. False for no swap
(default).
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Description
(Optional) Enables the query source port
53:
query-src-port-53—DNS packet
source port 53
(Optional) Enables the query stream
length:
query-stream-len—DNS Packet
Length
(Optional) Enables the query type:
query-type—DNS Query Type 2
Byte Value
(Optional) Enables the query value:
query-value—Query 0 Response 1
SERVICE Engines
Value
true | false
0 to 65535
0 to 65535
true | false
Value
from-service
to-service
bad-port-cmd-address
bad-port-cmd-port
pasv
1
0 to 65535
a-b[,c-d]
true | false
B-15

Advertisement

Table of Contents
loading

Table of Contents