5-4
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter5 Configuring Virtual Sensors
Normalization and Inline TCP Evasion Protection Mode
Virtual Sensor—All packets with the same session key (AaBb) within a virtual sensor belong to the
same session. This is the default and almost always the best option to choose.
Normalization and Inline TCP Evasion Protection Mode
Note
For the ASA IPS modules (ASA 5500-X IPS SSP and ASA 5585-X IPS SSP), normalization is
performed by the adaptive security appliance and not the IPS.
Normalization only applies when the sensor is operating in inline mode. The default is strict evasion
protection, which is full enforcement of TCP state and sequence tracking. The Normalizer enforces
duplicate packets, changed packets, out-of-order packets, and so forth, which helps prevent attackers
from evading the IPS.
Asymmetric mode disables most of the Normalizer checks. Use asymmetric mode only w hen the entire
stream cannot be inspected, because in this situation, attackers can now evade the IPS.
HTTP Advanced Decoding
HTTP advanced decoding facilitates analysis of encoded HTTP return web traffic by using on-the-fly
decoding. Changes to HTTP advanced decoding take effect immediately and only affect the new traffic
flows.
Restrictions
The following restrictions apply when you enable HTTP advanced decoding:
Although HTTP advanced decoding does not fire any new signatures, drop packets, or modify
traffic, it allows existing signatures to match on content that was previously not detectable because
of encodings.
HTTP advanced decoding only acts on return web response traffic.
Caution
Enabling HTTP advanced decoding severely impacts system performanc e.
Note
Because HTTP advanced decoding requires the Regex card and the String XL engi ne, it is available only
to those platforms that have them. HTTP advanced decoding is supported on the IPS 4345, IPS 4360,
IPS 4510, IPS 4520, ASA 5585-X IPS SSP, ASA 5525-X IPS SSP, ASA5545-X IPS SSP, and
ASA 5555-X IPS SSP.
Adding, Editing, and Deleting Virtual Sensors
This section describes how to add, edit, and delete virtual sensors, and contains the fo llowing topics:
Adding Virtual Sensors, page 5-5
Editing and Deleting Virtual Sensors, page 5-9