1-2
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 In troducing the CLI Configuration Guide
Sensor Configuration Sequence
For an alphabetical list of all IPS commands, refer to the Command Reference for Cisco Intrusion
Prevention System 7.2. For information on locating all IPS 7.2 documents on Cisco.com, refer to the
Documentation Roadmap for Cisco Intrusion Prevention System 7.2.
You can also use an IPS manager to configure your sensor. For information on how to access
documentation that describes how to use IPS managers, refer to the Documentation Roadmap for Cisco
Intrusion Prevention System 7.2.
Sensor Configuration Sequence
Perform the following tasks to configure the sensor:
1.
Log in to the sensor.
2.
Initialize the sensor by running the setup command.
3.
Verify the sensor initialization.
4.
Create the service account. A service account is needed for special debug situations directed by
TAC.
Note
Only one user with the role of service is allowed.
5.
License the sensor.
6.
Perform the other initial tasks, such as adding users and trusted hosts, and so forth.
7.
Make changes to the interface configuration if necessary. You configure the interfaces during
initialization.
8.
Add or delete virtual sensors as necessary. You configure the virtual sensors during initialization.
9.
Configure event action rules.
10.
Configure the signatures for intrusion prevention.
11.
Configure the sensor for global correlation.
12.
Configure anomaly detection if needed. You can run anomaly detection using the default values or
you can tailor it to suit your network needs.
Note
Anomaly detection is disabled by default. You must enable it to configure or apply an
anomaly detection policy. Enabling anomaly detection results in a decrease in performance.
13.
Set up any external product interfaces if needed. The CSA MC is the only external product
supported by the Cisco IPS.
14.
Configure IP logging if needed.
15.
Configure blocking if needed.
16.
Configure SNMP if needed.
17.
Perform miscellaneous tasks to keep your sensor running smoothly.
18.
Upgrade the IPS software with new signature updates and service packs.
19.
Reimage the application partition when needed.