27-15
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Chapter27 Cisco IOS IPS
Edit IPS
Configured SDF Locations
A signature location is a URL that provides a path to an SDF. To find an SDF, the
router attempts to contact the first location in the list. If it fails, it tries each
subsequent location in turn until it finds an SDF.
Add Button
Click to add a URL to the list.
Edit Button
Click to edit a specified location.
Delete Button
Click to delete a specified location.
Engine Options The engine options are:
Fail Closed—By default, while the Cisco IOS
compiles a new signature for a particular engine, it
allows packets to pass through without scanning for
the corresponding engine. When enabled, this option
makes the Cisco IOS drop packets during the
compilation process.
Use Built-in Signatures (as backup)—If Cisco IOS
IPS does not find signatures or fails to load them from
the specified locations, it can use the CiscoIOS
built-in signatures to enable Cisco IOS IPS. This
option is enabled by default.
Deny Action on IPS Interface—We recommend this
when the router is performing load balancing. When
enabled, this option causes Cisco IOS IPS to enable
ACLs on Cisco IOS IPS interfaces instead of enabling
them on the interfaces from which attack traffic came.
Shun Events This option uses the Shun Time parameter. Shun Time is
the amount of time that shun actions are to be in effect. A
shun action occurs if a host or network is added to an ACL
to deny traffic from that host or network.