System Properties>Intrusion Detection>
IDS Policy
The IDS Policy panel allows you to define Intrusion Detection System (IDS) policies. By defining IDS policies,
you instruct the PIX Firewall to audit IP traffic going through the PIX Firewall, looking for pre-defined attack
and informational signatures. For each IDS policy, you can instruct the PIX Firewall to send an alarm (syslog),
drop the offending packet and/or reset the offending connection. You can also selectively enable your IDS
policies on one or more of the PIX Firewall interfaces.
Auditing is performed by looking at the IP packets as they arrive at an input interface. If a packet triggers a
signature and the configured action does not drop the packet, then the same packet can trigger other signatures.
PIX Firewall supports both inbound and outbound auditing. For a complete list of supported Cisco Secure IDS
signatures, their wording, and whether they are attack or informational messages, refer to
System Log Messages
for the Cisco Secure PIX Firewall
for the your PIX Firewall software version.
The following sections are included in this Help topic:
Field Descriptions
●
Add
●
Edit
●
Delete
●
Selecting IP Attack and IP Informational Actions
●
Resetting to Last Applied Settings
●
Field Descriptions
The IDS Policy panel displays the following fields:
Intrusion Detection Policy table
Name—Displays the names of IDS rules you have defined.
❍
Type—Describes the type of rule: Info or Attack.
❍
Action—Defines the action taken when this rule is triggered. Alarm indicates that when a signature
match is detected, PIX Firewall reports the event to all configured syslog servers. Drop drops the
offending packet. Reset drops the offending packet and closes the connection if it is part of an active
connection.
❍
●
Add—Opens the Add dialog box.
●
Edit—Opens the Edit dialog box.
●
Содержание PIX 520 - PIX Firewall 520
Страница 45: ...Copyright 2001 Cisco Systems Inc ...
Страница 68: ...Copyright 2001 Cisco Systems Inc ...
Страница 74: ...Copyright 2001 Cisco Systems Inc ...
Страница 87: ...Copyright 2001 Cisco Systems Inc ...
Страница 92: ...Copyright 2001 Cisco Systems Inc ...
Страница 107: ...The panel has these buttons OK Exits the panel Help Provides more information Copyright 2001 Cisco Systems Inc ...
Страница 108: ......
Страница 184: ......
Страница 197: ...Copyright 2001 Cisco Systems Inc ...
Страница 200: ......
Страница 232: ...Copyright 2001 Cisco Systems Inc ...
Страница 246: ...Copyright 2001 Cisco Systems Inc ...