Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-48
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Step 7
Look through the list of settings for this signature engine and chose the signature
ID that you want to tune. Type the following command to configure the
parameters for a specific signature:
sensor(config-vsc-virtualSensor-ATO)# signature SIGID
signature ID
For example, to tune signature ID 9019, type the following command:
sensor(config-vsc-virtualSensor-ATO)# signature sigID 9019
Step 8
Type ? at the prompt to see a list of configurable parameters.
sensor (config-vsc-virtualSensor-ATO-sig)# ?
AlarmDelayTimer Number of seconds to delay further signature
inspection after an alarm.
AlarmInterval Special Handling for timed events. Use
AlarmInterval Y with MinHits X for X alarms
in Y second interval.
AlarmSeverity The severity of this alert reported in the
alarm.
AlarmThrottle Technique used to limit alarm firings. FireAll
sends all alarms. FireOnce sends the firstalarm
then deletes the inspector. Summarize sends an
IntervalSummary alarm. GlobalSummarize sends
a GlobalSummary alarm.
AlarmTraits User-defined traits further describing this
signature.
CapturePacket Set to True to include the offending packet in
the alarm.
ChokeThreshold Threshold value of alarms-per-interval to
auto-switch Alarm
Throttle modes If ChokeThreshold is defined the sensor will
automatically switch AlarmThrottle modes when
a large volume of alarms is seen in the
ThrottleInterval.
default Set the value back to the system default
setting
DstIpAddr IP address (or network) to match on the
IP packet's destination address. Must be used
with DstIpMask.
DstIpMask IP netmask used with DstIpAddr to match on the
IP packet's destination address. Must be used
with DstIpAddr.
DstPort A single Destination Port to match.
Enabled True to Enable the Sig. False to Disable
the Sig.
EventAction What action(s) to perform when the alarm is
fired.
exit Exit signatures configuration submode
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...