Cisco Systems IPS 7.1 Home Security System User Manual


  Open as PDF
of 1042
 
9-16
Cisco Intrusion Prevention System CLI Sensor Configuration Guide for IPS 7.1
OL-19892-01
Chapter 9 Configuring Anomaly Detection
Configuring the Internal Zone
enabled: true <defaulted>
-----------------------------------------------
sensor(config-ano-int-tcp)#
Configuring UDP Protocol for the Internal Zone
Use the udp {enabled | dst-port number | default-thresholds} command in service anomaly detection
internal zone submode to enable and configure the UDP service. The following options apply:
enabled {false | true}—Enables/disables UDP protocol.
default-thresholds—Defines thresholds to be used for all ports not specified in the destination port
map:
threshold-histogram {low | medium | high} num-source-ips number—Sets values in the
threshold histogram.
scanner-threshold—Sets the scanner threshold. The default is 200.
dst-port number—Defines thresholds for specific destination ports. The valid values are 0 to 65535.
enabled {true | false}—Enables/disables the service.
override-scanner-settings {yes | no}—Lets you override the scanner values:
threshold-histogram {low | medium | high} num-source-ips number—Sets values in the
threshold histogram.
scanner-threshold—Sets the scanner threshold. The default is 200.
Configuring the Internal Zone UDP Protocol
To configure UDP protocol for a zone, follow these steps:
Step 1 Log in to the CLI using an account with administrator privileges.
Step 2 Enter anomaly detection internal zone submode.
sensor# configure terminal
sensor(config)# service anomaly-detection ad0
sensor(config-ano)# internal-zone
sensor(config-ano-int)#
Step 3 Enable UDP protocol.
sensor(config-ano-int)# udp
sensor(config-ano-int-udp)# enabled true
Step 4 Associate a specific port with UDP protocol.
sensor(config-ano-int-udp)# dst-port 20
sensor(config-ano-int-udp-dst)#
Step 5 Enable the service for that port.
sensor(config-ano-int-udp-dst)# enabled true
Step 6 To override the scanner values for that port. You can use the default scanner values, or you can override
them and configure your own scanner values.
sensor(config-ano-int-udp-dst)# override-scanner-settings yes
sensor(config-ano-int-udp-dst-yes)#