Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-38
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
To configure alarm channel event filters, follow these steps:
Step 1
Log in to the CLI using an account with administrator or operator privileges.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Enter alarm channel configuration mode:
sensor(config)# service alarm-channel-configuration virtualAlarm
Step 4
Enter tune alarm channel submode:
sensor(config-acc)# tune-alarm-channel
Step 5
Enter event filter submode:
sensor(config-acc-virtualAlarm)# eventFilter
Step 6
Type the following command to configure a filter:
sensor(config-acc-virtualAlarm-Eve)# Filters SIGID
signature-id
SubSig
sub-id
SourceAddrs
ipaddress
DestAddrs
ipaddress
Exception true | false
The following options apply to the command:
•
SIGID—Signature IDs of events to which this filter should be applied. You
can use a list (2001,2004), or a range (2001–2004), an asterisk (*) for all
signatures, or one of the SIG variables if you defined them. If you use a
variable, you must use a dollar sign ($SIG1) in front of the variable. See
Configuring Alarm Channel System Variables, page 10-35
, for more
information.
•
SubSig—SubSignature IDs of events to which this filter should be applied.
•
Exception—Specifies if this filter identifies an exception to an existing filter.
By default, the exception value is False to indicate that this filter does not
identify an exception to another filter.
•
SourceAddrs—Source addresses of events to which this filter should be
applied. You can use one of the DMZ or USER-ADDR variables if you
defined them. If you use a variable, you must use a dollar sign
($USER-ADDRS1) in front of the variable. See
Configuring Alarm Channel
System Variables, page 10-35
, for more information.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...