Cisco Systems IPS4510K9 manual Configuring the External Zone Other Protocols

Models: IPS4510K9

1 854
Download 854 pages 14.35 Kb
Page 319
Image 319

Chapter 9 Configuring Anomaly Detection

Configuring the External Zone

 

 

Configuring the External Zone Other Protocols

 

 

To configure other protocols for a zone, follow these steps:

 

 

 

 

Step 1

Log in to the CLI using an account with administrator privileges.

 

Step 2

Enter anomaly detection external zone submode.

 

 

sensor# configure terminal

 

 

sensor(config)# service anomaly-detection ad0

 

 

sensor(config-ano)# external-zone

 

 

sensor(config-ano-ext)#

 

Step 3

Enable the other protocols.

 

 

sensor(config-ano-ext)# other

 

 

sensor(config-ano-ext-oth)# enabled true

 

Step 4

Associate a specific number for the other protocols.

 

 

sensor(config-ano-ext-oth)# protocol-number 5

 

 

sensor(config-ano-ext-oth-pro)#

 

Step 5

Enable the service for that port.

 

 

sensor(config-ano-ext-oth-pro)# enabled true

 

Step 6

Override the scanner values for that protocol. You can use the default scanner values, or you can override

 

 

them and configure your own scanner values.

 

 

sensor(config-ano-ext-oth-pro)# override-scanner-settings yes

 

 

sensor(config-ano-ext-oth-pro-yes)#

 

Step 7

Add a histogram for the new scanner settings. Enter the number of destination IP addresses (low,

 

 

medium, or high) and the number of source IP addresses you want associated with this histogram.

 

 

sensor(config-ano-ext-oth-pro-yes)#threshold-histogram high num-source-ips 75

 

Step 8

Set the scanner threshold.

 

 

sensor(config-ano-ext-oth-pro-yes)# scanner-threshold 100

 

Step 9

Configure the default thresholds for all other unspecified ports.

 

 

sensor(config-ano-ext-oth-pro-yes)# exit

 

 

sensor(config-ano-ext-oth-pro)# exit

 

 

sensor(config-ano-ext-oth)# default-thresholds

 

 

sensor(config-ano-ext-oth-def)# default-thresholds

 

 

sensor(config-ano-ext-oth-def)#threshold-histogram medium num-source-ips 120

 

 

sensor(config-ano-ext-oth-def)# scanner-threshold 120

 

Step 10

Verify the other protocols configuration settings.

 

 

sensor(config-ano-ext-oth)# show settings

 

 

other

 

 

-----------------------------------------------

 

 

 

 

 

protocol-number (min: 0, max: 255, current: 1)

 

 

-----------------------------------------------

 

 

 

 

 

number: 5

 

 

-----------------------------------------------

 

 

 

 

 

override-scanner-settings

 

 

-----------------------------------------------

 

 

 

 

 

yes

 

 

-----------------------------------------------

 

 

 

 

 

scanner-threshold: 95 default: 200

 

 

threshold-histogram (min: 0, max: 3, current: 1)

 

 

Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2

 

 

 

 

 

 

OL-29168-01

 

 

9-35

 

 

 

 

 

Page 319
Image 319
Cisco Systems IPS4510K9 manual Configuring the External Zone Other Protocols