Contents
xv
User Guide for Cisco Security MARS Local Controller
78-17020-01
C H A P T E R
21
Rules
21-1
Rules Overview
21-1
Prioritizing and Identifying
21-2
Think Like a Black Hat
21-2
Planning an Attack
21-2
Back to Being the Admin
21-3
Types of Rules
21-4
Inspection Rules
21-4
Global User Inspection Rules
21-4
Drop Rules
21-4
Constructing a Rule
21-5
Working Examples
21-16
Example A: Excessive Denies to a Particular Port on the Same Host
21-16
Example B: Same Source Causing Excessive Denies on a Particular Port
21-16
Example C: Same Host, Same Destination, Same Port Denied
21-16
Working with System and User Inspection Rules
21-17
Change Rule Status—Active and Inactive
21-17
Duplicate a Rule
21-17
Edit a Rule
21-18
Add an Inspection Rule
21-19
Working with Drop Rules
21-21
Change Drop Rule Status— Active and Inactive
21-21
Duplicate a Drop Rule
21-21
Edit a Drop Rule
21-22
Add a Drop Rule
21-22
Setting Alerts
21-23
Configure an Alert for an Existing Rule
21-24
Rule and Report Groups
21-24
Rule and Report Group Overview
21-25
Global Controller and Local Controller Restrictions for Rule and Report Groups
21-26
Add, Modify, and Delete a Rule Group
21-27
Add, Modify, and Delete a Report Group
21-30
Display Incidents Related to a Rule Group
21-32
Create Query Criteria with Report Groups
21-33
Using Rule Groups in Query Criteria
21-34