10-13
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 0 Configuring Global Correlation
Troubleshooting Global Correlation
Step 7
Press Enter to apply your changes or enter
no
to discard them.
For More Information
For more information about participating in the SensorBase Network, see Participating in the
SensorBase Network, page 10-2.
Troubleshooting Global Correlation
Make sure you observe the following when configuring global correlation:
Because global correlation updates occur through the sensor management interface, firewalls must
allow port 443/80 traffic.
You must have an HTTP proxy server or a DNS server configured to allow global correlation
features to function.
If you have an HTTP proxy server configured, the proxy must allow port 443/80 traffic from IPS
systems.
You must have a valid IPS license to allow global correlation features to function.
Global correlation features only contain external IP addresses, so if you position a sensor in an
internal lab, you may never receive global correlation information.
Make sure your sensor supports the global correlation features.
Make sure your IPS version supports the global correlation features.
For More Information
For the procedure for configuring a DNS or HTTP proxy server, see Configuring the DNS and Proxy
Servers for Global Correlation and Automatic Update, page 3-10 .
For the procedure for obtaining an IPS license, see Installing the License Key, page3-54.
Disabling Global Correlation
If your sensor is deployed in an environment where a DNS server or HTTP proxy server is not available,
you may want to disable global correlation so that global correlation health does not appear as red in the
overall sensor health, thus indicating a problem. You can also configure sensor health to exclude global
correlation status.
The following options apply:
global-correlation-inspection {on | off}—Turns global corre lation inspection on or off. When
turned on, the sensor uses updates from the SensorBase network to adjust the risk rating. The default
is on.
reputation-filtering {on | off}—Turns reputation filtering on or off. When turned on, the sensor
denies access to malicious hosts that are listed in the global correlation database. The default is on.
network-participation—Sets the level of network participation. The default is off.
off—No data is contributed to the SensorBase network.
partial—Data is contributed to the SensorBase network but potentially sensitive information is
withheld.