7-33
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter7 Defining Signatures
Configuring Signatures
1306 0 TCP Option Other Fires when a TCP option in the
range of TCP Option Number is
seen. All 1306 signatures fire
an alert and do not function in
promiscuous mode.
TCP Option Number
6-7,9-255
(Integer Range Allow
Multiple 0-255
constraints)
TCP Idle Timeout
3600
Modify Packet Inline
Produce Alert
10
1306 1 TCP SACK Allowed Option Fires when a TCP selective
ACK allowed option is seen.
All 1306 signatures fire an alert
and do not function in
promiscuous mode.
TCP Idle Timeout
3600
Modify Packet Inline
11
1306 2 TCP SACK Data Option Fires when a TCP selective
ACK data option is seen. All
1306 signatures fire an alert and
do not function in promiscuous
mode.
TCP Idle Timeout
3600
Modify Packet Inline
12
1306 3 TCP Timestamp Option Fires when a TCP timestamp
option is seen. All 1306
signatures fire an alert and do
not function in promiscuous
mode.
TCP Idle Timeout
3600
Modify Packet Inline
13
1306 4 TCP Window Scale Option Fires when a TCP window scale
option is seen. All 1306
signatures fire an alert and do
not function in promiscuous
mode.
TCP Idle Timeout
3600
Modify Packet Inline
14
1306 5 TCP MSS Option Fires when a TCP MSS option
is detected. All 1306 signatures
fire an alert and do not function
in promiscuous mode.
TCP Idle Timeout
3600
Modify Packet Inline
1306 6 TCP option data after EOL option Fires when the TCP option list
has data after the EOL option.
All 1306 signatures fire an alert
and do not function in
promiscuous mode.
TCP Idle Timeout
3600
Modify Packet Inline
1307 TCP Window Variation Fires when the right edge of the
recv window for TCP moves to
the right (decreases).
TCP Idle Timeout
3600
Deny Connection Inline
Produce Alert
15
1308 TTL Evasion
16
Fires when the TTL seen on one
direction of a session is higher
than the minimum that has been
observed.
TCP Idle Timeout
3600
Modify Packet Inline
17
Table7-6 TCP Stream Reassembly Signatures (continued)
Signature ID and Name Description
Parameter With
Default Value and
Range Default Actio ns