Cisco Systems IPS 7.1 Home Security System User Manual


  Open as PDF
of 1042
 
7-32
Cisco Intrusion Prevention System CLI Sensor Configuration Guide for IPS 7.1
OL-19892-01
Chapter 7 Configuring Event Action Rules
Configuring OS Identifications
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
passive-traffic-analysis: Enabled default: Enabled
-----------------------------------------------
ips-ssp(config-eve-os)#
Step 16 Exit event action rules submode.
sensor(config-eve-os)# exit
sensor(config-eve)# exit
Apply Changes:?[yes]:
Step 17 Press Enter to apply your changes or enter no to discard them.
Displaying and Clearing OS Identifications
Use the show os-identification [virtual-sensor] learned [ip-address] command in EXEC mode to
display OS IDs associated with IP addresses that were learned by the sensor through passive analysis.
Use the clear os-identification [virtual-sensor] learned [ip-address] command in EXEC mode to delete
OS IDs associated with IP addresses that were learned by the sensor through passive analysis.
When you specify an IP address, only the OS identification for the specified IP address is displayed or
cleared. If you specify a virtual sensor, only the OS identifications for the specified sensor is displayed
or cleared. If you specify an IP address without a virtual sensor, the IP address is displayed or cleared
on all virtual sensors.
The following options apply:
virtual-sensor—(Optional) Specifies the learned addresses of the virtual sensor that should be
displayed or cleared.
ip-address—(Optional) Specifies the IP address to query or clear. The sensor displays or clears the
OS ID mapped to the specified IP address.
Displaying and Clearing OS Identifications
To display and clear OS IDs, follow these steps:
Step 1 Log in to the CLI using an account with administrator or operator privileges.
Note An account with viewer privileges can display OS IDs.
Step 2 Display the learned OS IDs associated with a specific IP address.
sensor# show os-identification learned 192.0.2.0
Virtual Sensor vs0:
10.1.1.12 windows
sensor# show os-identification learned
Virtual Sensor vs0:
10.1.1.12 windows
Virtual Sensor vs1:
10.1.0.1 unix
10.1.0.2 windows
10.1.0.3 windows
sensor#