9-18
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter9 Co nfiguring Anomaly Detection
Configuring the Internal Zone
sensor(config-ano-int-udp)#
Configuring Other Protocols for the Internal Zone
Use the other {enabled | protocol number | default-thresholds} command in service anomaly detection
internal zone submode to enable and configure the other services.
The following options apply:
enabled {false | true}—Enables/disables other protocols.
default-thresholds—Defines thresholds to be used for all ports not specified in the destination port
map:
threshold-histogram {low | medium | high} num-source-ips number—Sets values in the
threshold histogram.
scanner-threshold—Sets the scanner threshold. The default is 200.
protocol-number number—Defines thresholds for specific protocols. The valid values are 0 to 255.
enabled {true | false}—Enables/disables the service.
override-scanner-settings {yes | no}—Lets you override the scanner values:
threshold-histogram {low | medium | high} num-source-ips number—Sets values in the
threshold histogram.
scanner-threshold—Sets the scanner threshold. The default is 200.
Configuring the Internal Zone Other Protocol s
To configure other protocols for a zone, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter anomaly detection internal zone submode.
sensor# configure terminal
sensor(config)# service anomaly-detection ad0
sensor(config-ano)# internal-zone
sensor(config-ano-int)#
Step 3
Enable the other protocols.
sensor(config-ano-int)# other
sensor(config-ano-int-oth)# enabled true
Step 4
Associate a specific number for the other protocols.
sensor(config-ano-int-oth)# protocol-number 5
sensor(config-ano-int-oth-pro)#
Step 5
Enable the service for that port.
sensor(config-ano-int-oth-pro)# enabled true
Step 6
To override the scanner values for that protocol. You can use the default scanner values, or you can
override them and configure your own scanner values.
sensor(config-ano-int-oth-pro)# override-scanner-settings yes
sensor(config-ano-int-oth-pro-yes)#