Cisco Systems IPS 7.1 Home Security System User Manual


  Open as PDF
of 1042
 
8-35
Cisco Intrusion Prevention System CLI Sensor Configuration Guide for IPS 7.1
OL-19892-01
Chapter 8 Defining Signatures
Configuring Signatures
1330 3 TCP Drop - Bad Option List Fires when TCP packet
has a bad option list.
Deny Packet Inline
1330 4 TCP Drop - Bad Option Length Fires when TCP packet
has a bad option length.
Deny Packet Inline
1330 5 TCP Drop - MSS Option Without
SYN
Fires when TCP MSS
option is seen in packet
without the SYN flag set.
Modify Packet Inline
clears the MSS
option.
Modify Packet Inline
1330 6 TCP Drop - WinScale Option
Without SYN
Fires when TCP window
scale option is seen in
packet without the SYN
flag set.
Modify Packet Inline
clears the window
scale option.
Modify Packet Inline
1330 7 TCP Drop - Bad WinScale Option
Value
Fires when a TCP packet
has a bad window scale
value.
Modify Packet Inline
sets the value to the
closest constraint
value.
Modify Packet Inline
1330 8 TCP Drop - SACK Allow Without
SYN
Fires when the TCP
SACK allowed option is
seen in a packet without
the SYN flags set.
Modify Packet Inline
clears the SACK
allowed option.
Modify Packet Inline
1330 9 TCP Drop - Data in SYN|ACK Fires when TCP packet
with SYN and ACK flags
set also contains data.
Deny Packet Inline
1330 10 TCP Drop - Data Past FIN Fires when TCP data is
sequenced after FIN.
Deny Packet Inline
1330 11 TCP Drop - Timestamp not
Allowed
Fires when TCP packet
has timestamp option
when timestamp option is
not allowed.
Deny Packet Inline
1330 12 TCP Drop - Segment Out of Order Fires when TCP segment
is out of order and cannot
be queued.
Deny Packet Inline
1330 13 TCP Drop - Invalid TCP Packet Fires when TCP packet
has invalid header.
Deny Packet Inline
1330 14 TCP Drop - RST or SYN in
window
Fires when TCP packet
with RST or SYN flag
was sent in the sequence
window but was not the
next sequence.
Deny Packet Inline
1330 15 TCP Drop - Segment Already
ACKed
Fires when TCP packet
sequence is already
ACKed by peer
(excluding keepalives).
Deny Packet Inline
Table 8-6 TCP Stream Reassembly Signatures (continued)
Signature ID and Name Description
Parameter With
Default Value and
Range Default Actions