Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-54
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Step 6
Type the following command to configure the parameters for a specific signature
and subsignature:
sensor(config-vsc-virtualSensor-ATO)# signature SIGID
signature ID
SubSig
SubSig ID
For example, to tune signature ID 9019, type the following command:
sensor(config-vsc-virtualSensor-ATO)# signature sigID 9019 SubSig 0
Step 7
View the signature settings:
sensor(config-vsc-virtualSensor-ATO)# show settings
A summary of the signatures and settings is displayed.
Step 8
Set the EventAction parameter to log.
sensor(config-vsc-virtualSensor-ATO-sig)# EventAction log
Note
If in Step 7 you saw other actions set for EventAction, you can combine
these with the log action by placing the | between the actions, for example
log|shunHost. Do not use spaces between | and the actions.
Note
To return any value to the default setting, type the keyword default before
the parameter name. For example, to remove IP logging from this
signature, type the following command: default EventAction.
Step 9
View your changes:
sensor(config-vsc-virtualSensor-ATO-sig)# show settings
The settings for this signature are displayed. In the example above, the settings
for the EventAction parameter would appear as
EventAction: log
.
Step 10
Exit tuning mode for this signature:
sensor(config-vsc-virtualSensor-ATO-sig)# exit
sensor(config-vsc-virtualSensor-ATO)# exit
sensor(config-vsc-virtualSensor)# exit
Apply Changes?:[yes]:
Step 11
Type yes to apply the changes.
The
Processing config:
message is displayed.
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...