10-7
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 0 Configuring Global Correlation
Global Correlation Requirements
Global Correlation Requirements
Global correlation has the following requirements:
Valid license—You must have a valid sensor license for global correlation features to function. You
can still configure and display statistics for the global correlation features, but the global correlation
databases are cleared and no updates are attempted. Once you install a valid license, the global
correlation features are reactivated.
Network Participation disclaimer—You must agree to the disclaimer to participate.
External connectivity for the sensor and a DNS server—The global correlation features of Cisco IPS
require the sensor to connect to the Cisco SensorBase Network. Domain name resolution is also
required for these features to function. You can either configure the sensor to connect through an
HTTP proxy server that has a DNS client running on it, or you c an assign an Internet routeable
address to the management interface of the sensor and configure the sensor to use a DNS server. In
Cisco IPS the HTTP proxy and DNS servers are used only by the global correlation features.
If you are connecting through an HTTP proxy, make sure you have the following configuration :
The proxy must allow HTTP requests from the IPS systems to http://updates.ironport.com/ibrs/
on port 80.
The proxy must allow HTTPS requests from the IPS systems to update-manifests.ironport.com
on port 443.
The firewall must allow access from the proxy to the internet (any destination address) on ports
80 and 443.
If you are NOT connecting through the HTTP proxy:
The firewall must allow access from each IPS to the Internet (any destination address) on ports
80 and 443.
Note
The IPS does not support the use of authenticated proxies.
Sensors deployed in an environment with a slow command and control connection w ill be slow to
download global correlation updates.
No IPv6 address support—Global correlation inspection and the reputation filtering deny features
do not support IPv6 addresses. For global correlation inspection, the sensor does not receive or
process reputation data for IPv6 addresses. The risk rating for IPv6 addresses is not modified for
global correlation inspection. Similarly, network participation does not include event data for
attacks from IPv6 addresses. And finally, IPv6 addresses do not appear in the deny list.
Sensor in inline mode—The sensor must operate in inline mode so that the global correlation
features can increase efficacy by being able to use the inline deny actions.
Sensor that supports the global correlation features
IPS version that supports the global correlation features
For More Information
For information on how to obtain and install a sensor license, see Installing the License Key,
page 3-54.
For information about the Network Participation disclaimer, see Participating in the SensorBase
Network, page 10-2.