10-9
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 0 Configuring Global Correlation
Configuring Global Correlation Inspection and Reputation Filtering
Understanding Global Correlation Inspection and Reputation Filtering
You can configure the sensor to use updates from the SensorBase Network to adjust the risk rating. The
client determines which updates are available and applicable to the sensor by communicating with the
global correlation update server and a file server, which is a two-phase process. In the first phase the
sensor sends a client manifest to the global correlation update sever via an HTTPS POST request. The
server then returns the server manifest document in the HTTPS response. In the next phase the sensor
identifies the updates that are available and how to obtain them from a file server. The sensor downloads
the encrypted update files via HTTP from the file server using the information in the server manifest.
The integrity of these update files has been verified by comparing its MD5 hash with the hash value
specified in the server manifest.
Figure 10-2 demonstrates how the global correlation update client obtains the files.
Figure 10-2 Global Correlation Update Client
Caution
You must have a valid sensor license for global correlation features to function. You can still configure
and display statistics for the global correlation features, but the global correlation databases are cleared
and no updates are attempted. Once you install a valid license, the global correlation features are
reactivated.
Once you configure global correlation, updates are automatic and happen at regular intervals,
approximately every five minutes by default, but this interval may be modified by the global correlation
server. The sensor gets a full update and then applies an incremental update periodically.
You configure an HTTP proxy or a DNS server in the service network-setting submode. If you turn on
global correlation, you can choose how aggressively you want the deny actions to be enforced against
malicious hosts. You can then enable reputation filtering to deny access to known malicious hosts. If you
only want a report of what could have happened, you can enab le test-global-correlation. This puts the
sensor in audit mode, and actions the sensor would have performed are generated in the events.
Use the show health command in privileged EXEC mode to display the overall health status information
of the sensor. The health status categories are rated by red and green with red being critical.
Caution
As with signature updates, when the sensor applies a global correlation update, it may trigger bypass.
Whether or not bypass is triggered depends on the traffic load of the sensor and the size of the
signature/global correlation update. If bypass mode is turned off, an inline sensor stops passing traffic
while the update is being applied.
Client Manifest
Server Manifest
Global
Correlation
Update Server
File
Server
Update Files
251233
Global
Correlation
Client