10-49
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
FlipAddr True if address (and ports) Source and
Destination are swapped in the alarm message.
False for no swap (normal).
MaxInspectLength Maximum number of bytes to inspect.
MaxTTL Maximum number of seconds to inspect a
logical stream. The inspector is deleted after X
seconds of being active.
MinHits Minimum number of signature hits before the
alarm message is sent. This a limiter for
firing the alarm only after X times of seeing
the signature on the address key.
MinUDPLength Fire alarm when packet UDP LENGTH is less
than this.
Protocol Protocol of interest for this inspector.
ResetAfterIdle Number of seconds to wait to reset signature
counters after the host(s) were idle.
ShortUDPLength Fire alarm when IP Data length is less than
UDP Header Length
show Display system settings and/or history
information
SigComment USER NOTES - miscellaneous information about
this signature
SigStringInfo Extra information included in the alarm message.
SigVersion Signature update version of signature
SrcIpAddr IP address (or network) to match on the IP
packet's source address. Must be used with
SrcIpMask.
SrcIpMask IP netmask used with SrcIpAddr to match on
the IP packet's destination address. Must be
used with SrcIpAddr.
SrcPort A single Source Port to match.
StorageKey Type of Address Key used to store persistent
data.
SummaryKey The Storage Type on which to summarize this
signature.
ThrottleInterval Number of seconds defining an Alarm Throttle
interval. This is used with the AlarmThrottle
parameter to tune special alarm limiters.
WantFrag True if a fragment is desired. False if a
fragment is not desired. Any for either.
Step 9
Type the name of the parameter that you want to configure and add or change the
values.
For example, to change the destination port for signature ID 9019 from the default
2140 to 2139, type the following command:
sensor(config-vsc-virtualSensor-ATO-sig)# dstport 2139
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...