5-10
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter5 Configuring Virtual Sensors
Adding, Editing, and Deleting Virtual Sensors
Step 8
Change the inline TCP session tracking mode. The default is virtual sensor mode, which is almost always the best option to choose.
sensor(config-ana-vir)# inline-TCP-session-tracking-mode interface-and-vlan
Step 9
Display the list of available interfaces.
sensor(config-ana-vir)# physical-interface ?
GigabitEthernet0/0 GigabitEthernet0/0 physical interface.
GigabitEthernet0/1 GigabitEthernet0/1 physical interface.
GigabitEthernet2/0 GigabitEthernet0/2 physical interface.
GigabitEthernet2/1 GigabitEthernet0/3 physical interface.
sensor(config-ana-vir)# physical-interface
sensor(config-ana-vir)# logical-interface ?
<none available>
Step 10
Change the promiscuous mode interfaces assigned to this virtual sensor.
sensor(config-ana-vir)# physical-interface GigabitEthernet0/2
Step 11
Change the inline interface pairs assigned to this virtual sensor. You must have already paired the interfaces.
sensor(config-ana-vir)# logical-interface inline_interface_pair_name
Step 12
Change the subinterface with the inline VLAN pairs or groups assigned to this virtual sensor. You must have already subdivided any interfaces into VLAN pairs or groups.
sensor(config-ana-vir)# physical-interface GigabitEthernet2/0 subinterface-number
subinterface_number
Step 13
Verify the edited virtual sensor settings.
ssensor(config-ana-vir)# show settings
name: vs1
-----------------------------------------------
description: virtual sensor 1 default:
signature-definition: sig1 default: sig0
event-action-rules: rules1 default: rules0
anomaly-detection
-----------------------------------------------
anomaly-detection-name: ad1 default: ad0
operational-mode: learn default: detect
-----------------------------------------------
physical-interface (min: 0, max: 999999999, current: 2)
-----------------------------------------------
name: GigabitEthernet0/3
subinterface-number: 0 <defaulted>
-----------------------------------------------
inline-TCP-session-tracking-mode: interface-and-vlan default: virtual-sensor
-----------------------------------------------
logical-interface (min: 0, max: 999999999, current: 0)
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
sensor(config-ana-vir)#
Step 14
Delete a virtual sensor.
sensor(config-ana-vir)# exit
sensor(config-ana)# no virtual-sensor vs1