B-41
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Appendix B Signature Engines
Service Engines
For More Information
For more information on the parameters common to all signature engines, see Master Engine, page B-4.
Service FTP Engine
The Service FTP engine specializes in FTP port command decode, trapping invalid port commands and
the PASV port spoof. It fills in the gaps when the String engine is not appropriate for detection. The
parameters are Boolean and map to the various error trap conditions in the port command decode. The
Service FTP engine runs on TCP ports 20 and 21. Port 20 is for data and the Service FTP engine does
not do any inspection on this. It inspects the control transactions on port 21.
specify-query-jump-count-exceeded
{yes |no}
(Optional) Enables query jump count
exceeded:
query-jump-count-exceeded—DNS
compression counter.
no | yes
specify-query-opcode {yes |no} (Optional) Enables query opcode :
query-opcode—Specifies the DNS
Query Opcode 1 byte Value.
0 to 65535
specify-query-record-data-invalid
{yes |no}
(Optional) Enables query record data
invalid:
query-record-data-invalid—Specifies t
he DNS Record Data incomplete.
no | yes
specify-query-record-data-len {yes
|no}
(Optional) Enables the query record data
length:
query-record-data-len—Specifies
the DNS Response Record Data
Length.
0 to 65535
specify-query-src-port-53 {yes |no} (Optional) Enables the query source port
53:
query-src-port-53—Specifies the
DNS packet source port 53.
no | yes
specify-query-stream-len {yes |no} (Optional) Enables the query stream
length:
query-stream-len—Specifies the
DNS Packet Length.
0 to 65535
specify-query-type {yes |no} (Optional) Enables the query type:
query-type—Specifies the DNS
Query Type 2 Byte Value.
0 to 65535
specify-query-value {yes |no} (Optional) Enables the query value:
query-value—Specifies the Query 0
Response 1.
no | yes
TableB-18 Service DNS Engine Parameters (continued)
Parameter Description Value