CHAPT ER
8-1
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
8
Configuring Event Action Rules
This chapter explains how to add event action rules policies and how to configure event action rules. It
contains the following sections:
Event Action Rules Notes and Caveats, page 8-1
Understanding Security Policies, page 8-2
Understanding Event Action Rules, page 8-2
Working With Event Action Rules Policies, page8-8
Event Action Variables, page8-9
Configuring Target Value Ratings, page8-13
Configuring Event Action Overrides, page 8-17
Configuring Event Action Filters, page 8-20
Configuring OS Identifications, page 8-26
Configuring General Settings, page 8-32
Configuring the Denied Attackers List, page 8-35
Monitoring Events, page 8-38

Event Action Rules Notes and Caveats

The following notes and caveats apply to configuring event action rules:
Rate limiting and blocking are not supported for IPv6 traffic. If a signature is configured with a
block or rate limit event action and is triggered by IPv6 traffic, an alert is generated but the action
is not carried out.
Global correlation inspection and the reputation filtering deny features do not support IPv6
addresses. For global correlation inspection, the sensor does not receive or process reputation data
for IPv6 addresses. The risk rating for IPv6 addr esses is not modified for global correlation
inspection. Similarly, network participation does not include event data for attacks from IPv6
addresses. And finally, IPv6 addresses do not appear in the deny list.
You must preface the event variable with a dollar ($) sign to indicate that you are using a variable
rather than a string.
Connection blocks and network blocks are not supported on adaptive security appliances. Adaptive
security appliances only support host blocks with additional connection information.