Chapter27 Cisco IOS IPS
Edit IPS
27-16
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Move Up an d Move Down Buttons
Use to change the order of preference for the URLs in the list.
Reload Signatures
Click to recompile signatures in all signature engines. During the time that
signatures are being recompiled in a signature engine, the CiscoIOS software can
not use that engine’s signatures to scan packets.
Edit Global Settings
Edit settings that affect the overall operation of Cisco IOS IPS in this window, in
the Syslog and SDEE and Global Engine tabs.
Enable Syslog Notification (Syslog and SDEE Tab)
Check this checkbox to enable the router to send alarm, event, and error messages
to a syslog server. A syslog server must be identified in System Properties for this
notification method to work.
SDEE (Syslog and SDEE Tab)
Enter the number of concurrent SDEE subscriptions, in the range of 1–3, in the
Number of concurrent SDEE subscriptions field. An SDEE subscription is a
live feed of SDEE events.
In the Maximum number of SDEE alerts to store field, enter the maximum
number of SDEE alerts that you want the router to store, in the range o f 10–2000.
Storing more alerts uses more router memory.
In the Maximum number of SDEE messages to store field, enter the maximum
number of SDEE messages that you want the router to store, in the range of
10–500. Storing more messages uses more router memory.
Enable Engine Fail Closed (Global Engine Tab)
By default, while the Cisco IOS software compiles a new signature for a par ticular
engine, it allows packets to pass through without scanning for the corresponding
engine. Enable this option to make the Cisco IOS software drop packets during
the compilation process.