Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-40
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Step 5
Display the list of signature engines:
sensor(config-vsc-virtualSensor)# ?
A list of all signature engine names and a description of each is displayed.
sensor(config-vsc-virtualSensor)# ?
ATOMIC.ARP Layer 2 ARP signatures.
ATOMIC.ICMP Simple ICMP alarms based on Type, Code,
Seq, Id
ATOMIC.IPOPTIONS Simple L3 Alarms based on Ip Options
ATOMIC.L3.IP Simple L3 IP Alarms.
ATOMIC.TCP Simple TCP packet alarms based on TCP
Flags, ports (both sides), and single
packet regex. Use SummaryKey to define
the address view for MinHits and
Summarize counting. For best
performance, use a StorageKey of xxxx.
ATOMIC.UDP Simple UDP packet alarms based on Port,
Direction and DataLength.
exit Exit service configuration mode
FLOOD.HOST.ICMP Icmp Floods directed at a single host
FLOOD.HOST.UDP UDP Floods directed at a single host
FLOOD.NET Multi-protocol floods directed at a
network segment. Ip Addresses are
wildcarded for this inspection.
FragmentReassembly Fragment Reassembly configuration tokens
IPLog Virtual Sensor IP log configuration
tokens
OTHER This engine is used to group generic
signatures so common parameters may be
changed. It defines an interface into
common signature parameters.
SERVICE.DNS DNS SERVICE Analysis Engine
SERVICE.FTP FTP service special decode alarms
SERVICE.GENERIC Custom service/payload decode and
analysis based on our quartet tuple
programming language. EXPERT use only.
SERVICE.HTTP HTTP protocol decode based string search
Engine. Includes anti-evasive URL
deobfuscation
SERVICE.IDENT Ident service (client and server)
alarms.
SERVICE.MSSQL Microsoft (R) SQL service inspection
engine
SERVICE.NTP Network Time Protocol based signature
engine
SERVICE.RPC RPC SERVICE analysis engine
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...