8-22
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter8 Configuring Event Action Rules
Configuring Event Action Filters
ipv6-attacker-address-range—Specifies the range set of IPv6 attacker address(es) for this item
(for example,
<XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX>-<XXXX:XXXX:XXXX:XXXX:
XXXX:XXXX:XXXX:XXXX>[,<XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX>-
<XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX>].
Note
The second IPv6 address in the range must be greater than or equal to the first IPv6 address.
If you do not specify an IPv6 attacker address range, all IPv6 attacker addresses are matched.
ipv6-victim-address-range—Specifies the range set of victim address(es) for this item (for
example,
<XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX>-<XXXX:XXXX:XXXX:XXXX:
XXXX:XXXX:XXXX:XXXX>[,<XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX>-
<XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX>].
Note
The second IPv6 address in the range must be greater than or equal to the first IPv6 address.
If you do not specify an IPv6 victim address range, all IPv6 victim addresses are matched.
no—Removes an entry or selection setting.
os-relevance—Specifies the event OS relevance for this filter:
relevant—Specifies that the event is relevant to the target OS.
not-relevant—Specifies that the event is not relevant to the target OS.
unknown—It is unknown whether the event is relevant to the target OS.
risk-rating-range—Specifies the range of risk rati ng values for this filter item.
signature-id-range—Specifies the range set of signature ID(s) for this item (for example,
1000-2000,3000-3000).
stop-on-match {true | false}—Specifies to continue evaluating filters or stop when this filter item
is matched.
subsignature-id-range—Specifies the range set of subsignature ID(s) for this item (for example,
0-2,5-5).
user-comment —Lets you add your comments about this filter item.
victim-address-range—Specifies the range set of victim address(es) for this item (for example,
10.20.1.0-10.20.1.255,10.20.5.0-10.20.5.255).
Note
The second IP address in the range must be greater then or equal to the first IP address. If
you do not specify a victim address range, all IPv4 attacker addresses are matched.
victim-port-range—Specifies the range set of victim port(s) for this item (for example,
147-147,8000-10000).