7-34
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter 7 Defining Signatures
Configuring Signatures
1309 TCP Reserved Flags Set Fires when the reserved bits
(including bits used for ECN)
are set on the TCP header.
TCP Idle Timeout
3600
Modify Packet Inline
Produce Alert
18
1311 TCP Packet Exceeds MSS Fires when a packet exceeds the
MSS that was exchanged
during the three-way
handshake.
TCP Idle Timeout
3600
Produce Alert
19
1312 TCP MSS Below Minimum Fires when the MSS value in a
packet containing a SYN flag is
less that TCP Min MSS.
TCP Min MSS 400
(0-16000)
TCP Idle Timeout
3600
Modify Packet Inline
20
1313 TCP Max MSS Fires when the MSS value in a
packet containing a SYN flag
exceed TCP Max MSS
TCP Max MSS1460
(0-16000)
Modify Packet Inline
disabled
21
1314 TCP Data SYN Fires when TCP payload is sent
in the SYN packet.
Deny Packet Inline
disabled
22
1315 ACK Without TCP Stream Fires when an ACK packet is
sent that does not belong to a
stream.
Produce Alert
disabled
23
1317 Zero Window Probe Fires when a zero window
probe packet is detected.
Modify Packet Inline
removes data from the
Zero Window Probe
packet.
Modify Packet Inline
1330
24
0 TCP Drop - Bad Checksum Fires when TCP packet has bad
checksum.
Modify Packet Inline
corrects the
checksum.
Deny Packet Inline
1330 1 TCP Drop - Bad TCP Flags Fires when TCP packet has bad
flag combination.
Deny Packet Inline
1330 2 TCP Drop - Urgent Pointer With
No Flag
Fires when TCP packet has a
URG pointer and no URG flag.
Modify Packet Inline
clears the pointer.
Modify Packet Inline
disabled
1330 3 TCP Drop - Bad Option List Fires when TCP packet has a
bad option list.
Deny Packet Inline
1330 4 TCP Drop - Bad Option Length Fires when TCP packet has a
bad option length.
Deny Packet Inline
1330 5 TCP Drop - MSS Option Without
SYN
Fires when TCP MSS option is
seen in packet without the SYN
flag set.
Modify Packet Inline
clears the MSS
option.
Modify Packet Inline
1330 6 TCP Drop - WinScale Option
Without SYN
Fires when TCP window scale
option is seen in packet without
the SYN flag set.
Modify Packet Inline
clears the window
scale option.
Modify Packet Inline
Table7-6 TCP Stream Reassembly Signatures (continued)
Signature ID and Name Description
Parameter With
Default Value and
Range Default Actio ns