Security Services
Intrusion Prevention Service
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
219
7
For example, if you choose BitTorrent, only the signatures under the
BitTorrent application are displayed. To display all signatures, choose
All
.
•
Search by Signature ID:
Allows you to view a specific signature by
searching the signature ID. Enter the signature ID in this field, and then click
Search
. To display all categories, click
Reset
.
•
Expand/Collapse:
To expand the signatures under an IM or P2P application,
click the
+
button. To hide the signatures, click the
-
button.
STEP 3
Specify the setting for all signatures under an IM or P2P application or for a single
signature:
•
Disabled:
Choose this option to disable checking attacks.
•
Detect Only:
Click this option to check the attacks and to log a message
when an attack is detected. This option is mostly used for troubleshooting
purposes.
•
Detect and Prevent:
Click this option to check the attacks, and to log a
message and drop the packet when an attack is detected.
To log the IPS events, you first need to choose
Detect Only
or
Detect and
Prevent
for the IM or P2P applications, and then go to the
Device
Management -> Loggings
pages to configure the log settings and log
facilities:
-
To save the IPS logs in the lcoal syslog daemon, you need to enable the
Log feature, set the log buffer size and the severity for local log, and then
check the
Local Log
box for the
IM/P2P Blocking
log facility.
-
To save the IPS logs to the remote syslog server if you have a remote
syslog server support, you need to enable the Log feature, specify the
Remote Log settings, and check the
Remote Log
box for the
IM/P2P
Blocking
log facility.
For more information about how to configure the log settings and log
facilities, and how to view the logs, see
•
Email Alert Threshold:
Enter the value of the email alert threshold. When the
hit count is over the email alert threshold, an alert email is sent to the
specified email acount.
To send the IPS alert emails to the specified email accont, you first need to
enable the IPS Alert feature and configure the email account settings, see
Configuring the Email Alert Settings, page 316
.