B-38
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
AppendixB Signature Engines
Normalizer Engine
ASA IPS Modules and the Normalizer Engine
The majority of the features in the Normalizer engine are not used on the ASA5500-X IPS SSP or
ASA 5585-X IPS SSP, because the ASA itself handles the normalization. Packets on the ASA IPS
modules go through a special path in the Normalizer that only r eassembles fragments and puts packets
in the right order for the TCP stream. The Normalizer does not do any of the normalization that is done
on an inline IPS appliance, because that causes problems in the way the ASA handles the packets.
The following Normalizer engine signatures are not supported :
1300.0
1304.0
1305.0
1307.0
1308.0
1309.0
1311.0
1315.0
1316.0
1317.0
1330.0
1330.1
1330.2
1330.9
1330.10
1330.12
1330.14
1330.15
1330.16
1330.17
1330.18
Tabl e B-17 lists the parameters that are specific to the Normalizer engine.
TableB-17 Normalizer Engine Parameters
Parameter Description
edit-default-sigs-only Editable signatures.
specify-fragment-reassembly-timeout (Optional) Enables fragment reassembly timeout.
specify-hijack-max-old-ack (Optional) Enables hijack-max-old-ack.
specify-max-dgram-size (Optional) Enables maximum datagram size.
specify-max-fragments (Optional) Enables maximum fragments:
max-fragments—Lets you specify the number of
maximum fragments.