B-57
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Appendix B Signature Engines
Service Engines
For More Information
For more information on the parameters common to all signature engines, see Master Engine,
page B-4.
For a list of the signature regular expression syntax, see Regular Expression Syntax, page B-9.
Service SNMP Engine
The Service SNMP engine inspects all SNMP packets destined for port161. You can tune SNMP
signatures and create custom SNMP signatures based on specific community names and objec t
identifiers.
Instead of using string comparison or regular expression operations to match the c ommunity name and
object identifier, all comparisons are made using the integers to speed up the protocol decode and reduce
storage requirements.
Tabl e B-29 lists the parameters specific to the Service SNMP engine.
TableB-29 Service SNMP Engine Parameters
Parameter Description Value
inspection-type Enables the SNMP inspection type. brute-force-inspection
(default)
invalid-packet-inspection
non-snmp-traffic-inspection
snmp-inspection
brute-force-inspection Enables brute forc e inspection:
brute-force-count—Specifies the
number of unique SNMP
community names that constitute a
brute force attempt.
0 to 65535
invalid-packet-inspection Inspects for SNMP protocol violations.