39-23
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter3 9 Configuring Event Action Rules
Configuring Settings for Event Actions
Maximum Number of Denied
Attackers
(IPS appliances and service
modules only.)
Limits the number of denied attackers possible in the system at any one
time.
The range is 0 to 100000000. The default is 10000.
Enable One Way TCP Reset
(IPS appliances and service
modules only.)
When selected, enables a one-way TCP reset for deny packet inline
actions for TCP-based alerts. Available only for sensors running IPS
6.1+ software.
The one-way TCP reset operates for inline mode only and is an
automatic addition to the deny packet inline actions. It sends a TCP
reset to the victim of the alert, thus creating a black hole for the attacker
and clearing the TCP resources of the victim.
Tips
In inline mode, all packets entering or leaving the network must
pass through the sensor.
An inline sensor denies packets for any alert with a risk rating of
greater than or equal to 90. It also issues a one-way TCP reset on
TCP alerts with a risk rating of greater than or equal to 90.
Table39-8 Event Actions Settings Policy (Continued)
Element Description