7-50

Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter 7 Defining Signatures
Creating Custom Signatures
component-sig-id: 1000
component-subsig-id: 0 default: 0
component-count: 1 default: 1
is-not-component: false <defaulted>
-----------------------------------------------
-----------------------------------------------
NAME: m2
-----------------------------------------------
component-sig-id: 1001
component-subsig-id: 0 <defaulted>
component-count: 1 <defaulted>
is-not-component: true default: false
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
meta-key
-----------------------------------------------
Axxx
-----------------------------------------------
unique-victims: 1 <defaulted>
-----------------------------------------------
-----------------------------------------------
component-list-in-order: false default: false
all-components-required: true default: true
all-nots-required: false default: false
-----------------------------------------------
sensor(config-sig-sig-met)#
Step 14
Exit signature definition submode.
sensor(config-sig-sig-met)# exit
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Step 15

Press Enter to apply the changes or enter

no

to discard them.

For More Information

For more information on Signature Event Action Processor, see Signature Event Action Processor,

page 8-3.

For more information on the Meta engine, see Meta Engine, page B-33.

Example IPv6 Engine Signature
Caution

A custom signature can affect the performance of your sensor. Test the custom signature against a

baseline sensor performance for your network to determine the overall impact of the signature.