17-14
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter17 Administrative Tasks for the Sensor
Configuring Health Status Information
memory-usage-policy {enable | disable} {true | false} red-threshold yellow-threshold—Lets you
set a threshold percentage for memory usage and whether this metric is applied to the overall sensor
health rating. The range is 0 to 100. The default for red is 91% and the default for yellow is 80%.
missed-packet-policy {enable | disable} {true | false} red-threshold yellow-threshold—Lets you
set a threshold percentage for missed packets and whether this metric is applied to the overall sensor
health rating.
network-participation-policy {enable | disable} {true | false}—Lets you apply this metric to the
overall sensor health rating.
persist-security-status—Lets you set the number of minutes that a lower security persists following
the occurrence of the latest event to lower the security status.
signature-update-policy {enable | disable} {true | false} red-threshold yellow-threshold—Lets
you set a threshold for the number of days elapsed since the last signature update and whether this
metric is applied to the overall sensor health rating. The range for the thr eshold is 0 to 4294967295
seconds
ASA 5500-X IPS SSP and Memory Usage
For the ASA 5500-X IPS SSP, the memory usage is 93%. The default health thresholds for the sensor
are 80% for yellow and 91% for red, so the sensor health will be shown as red on these platforms even
for normal operating conditions. You can tune the threshold percentage for memory usage so that it reads
more accurately for these platforms by configuring the memory-usage-policy option in the sensor health
metrics.
Note
Make sure you have the memory-usage-policy option in the sensor health metrics enabled.
Table 17-2 lists the yellow-threshold and red-threshold health values.
Configuring Health Statistics
To configure the health statistics for the sensor, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter service health monitor submode.
sensor# configure terminal
sensor(config)# service health-monitor
sensor(config-hea)#
Step 3
Enable the metrics for application failure status.
sensor(config-hea)# application-failure-policy
sensor(config-hea-app)# enable true
Table17-2 ASA 5500-X IPS SSP Memory Usage Values
Platform Yellow Red Memory Used
ASA 5512-X IPS SSP 85% 91% 28%
ASA 5515-X IPS SSP 88% 92% 14%
ASA 5525-X IPS SSP 88% 92% 14%
ASA 5545-X IPS SSP 93% 96% 13%
ASA 5555-X IPS SSP 95% 98% 17%