14-13
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 4 Configuring Attack Response Controller for Blocking and Rate Limiting
Disabling Blocking
-----------------------------------------------
ip-address: 192.0.2.1
-----------------------------------------------
-----------------------------------------------
never-block-networks (min: 0, max: 250, current: 1)
-----------------------------------------------
ip-address: 209.165.200.224/27
-----------------------------------------------
-----------------------------------------------
block-hosts (min: 0, max: 250, current: 0)
-----------------------------------------------
--MORE--
Step 8
Exit network access submode.
sensor(config-net-gen)# exit
sensor(config-net)# exit
Apply Changes:?[yes]:
Step 9
Press Enter to apply the changes or enter
no
to discard them.
Specifying the Block Time
Note
If you change the default block time, you are changing a signature parameter, which affects all
signatures.
Note
The time for manual blocks is set when you request the block.
Use the global-block-timeout command in the service event action rules submode to change the amount
of time an automatic block lasts. The default is 30 minutes. To change the default block time, follow
these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter event action rules submode.
sensor# configure terminal
sensor(config)# service event-action-rules rules0
sensor(config-rul)#
Step 3
Enter general submode.
sensor(config-rul)# general
Step 4
Specify the block time. The value is the time duration of the block event in minutes (0 to 10000000).
sensor(config-rul-gen)# global-block-timeout 60
Step 5
Verify the setting.
sensor(config-rul-gen)# show settings
general
-----------------------------------------------
global-overrides-status: Enabled <defaulted>
global-filters-status: Enabled <defaulted>