17-25
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 7 Administrative Tasks for the Sensor
Clearing the Denied Attackers List
No time source
Summer time starts 03:00:00 UTC Sun Mar 09 2011
Summer time stops 01:00:00 UTC Sun Nov 02 2011

Manually Setting the System Clock

Note
You do not need to set the system clock if your sensor is synchronized by a valid outside timing
mechanism such as an NTP clock source.
Use the clock set hh:mm [:ss] month day year command to manually set the clock on the appliance. Use
this command if no other time sources are available. The clock set command does not apply to the
following platforms, because they get their time from the adaptive security appliance in which they are
installed:
ASA 5500-X IPS SSP
ASA 5585-X IPS SSP
To manually set the clock on the appliance, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Set the clock manually.
sensor# clock set 13:21 Mar 29 2011
Note
The time format is 24-hour time.
Clearing the Denied Attackers List
Use the show statistics denied-attackers command to display the list of denied attackers. Use the clear
denied-attackers [virtual_sensor] [ip-address ip_address] command to delete the denied attackers list
and clear the virtual sensor statistics.
If your sensor is configured to operate in inline mode, the traffic is passing through the sensor. You can
configure signatures to deny packets, connections, and attackers while in inline mode, which means that
single packets, connections, and specific attackers are denied, that is, not transmitted, when the sensor
encounters them. When the signature fires, the attacker is denied and placed in a list. As part of sensor
administration, you may want to delete the list or clear the statistics in the list.
The following options apply:
virtual_sensor—(Optional) Specifies the virtual sensor whose denied attackers list should be
cleared.
ip_address—(Optional) Specifies the IP address to clear.