8-15
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter8 Configuring Event Action Rules
Configuring Target Value Ratings
Adding, Editing, and Deleting Target Value Ratings
Note
Global correlation inspection and the reputation filtering deny features do not support IPv6 addresses.
For global correlation inspection, the sensor does not receive or process reputation data for IPv6
addresses. The risk rating for IPv6 addresses is not modified for global co rrelation inspection. Similarly,
network participation does not include event data for attacks from IPv6 addresses. And finally, IPv6
addresses do not appear in the deny list.
Note
Rate limiting and blocking are not supported for IPv6 traffic. If a signature is configured with a block or
rate limit event action and is triggered by IPv6 traffic, an alert is generated but the action is not carried
out.
You can assign a target value rating to your network assets. The target value rating is one of the factors
used to calculate the risk rating value for each alert. You can assign different target value ratings to
different targets. Events with a higher ris k rating trigger more severe signature event actions.
For IPv4 address, use the target-value {zerovalue | low | medium | high | mission-critical}
target-address ip_address command in service event action rules submode to add target value ratings
for your network assets. The default is medium. Use the no target-value {zerovalue | low | medium |
high | mission-critical} command in service event action rules submode to delete target value ratings.
For IPv6 addresses, use the ipv6-target-value {zerovalue | low | medium | high | mission-crit ical}
ipv6-target-address ip_address command in service event action rules submode to add target value
ratings for your network assets. The default is medium. Use the no ipv6-target-value {zerovalue | low
| medium | high | mission-critical} command in service event action rules submode to delete target
value ratings.
The following options apply:
target-value—Specifies the IPv4 target value rating:
zerovalue—No value of this target.
low—Lower value of this target.
medium—Normal value of this target (default).
high—Elevated value of this target.
mission-critical—Extreme value of this target.
no target-value—Removes the IPv4 target value rating.
target-address ip_address—Specifies the range set of IP address(es) for IPv4 addresses in the
following form: <A.B.C.D>-<A.B.C.D>[,<A.B.C.D>-<A.B.C.D>]
ipv6-target-value—Specifies the IPv6 target value rating:
zerovalue—No value of this target.
low—Lower value of this target.
medium—Normal value of this target (default).
high—Elevated value of this target.
mission-critical—Extreme value of this target.
no ipv6-target-value—Removes the IPv6 target value rating.