B-58
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
AppendixB Signature Engines
Service Engines
For More Information
For more information on the parameters common to all signature engines, see Master Engine, page B-4.
Service SSH Engine
The Service SSH engine specializes in port22 SSH traffic. Because all but the setup of an SSH session
is encrypted, the Service SSH engine only looks at the fields in the setup. There are two default
signatures for SSH. You can tune these signatures, but you cannot create custom signatures.
Tabl e B-30 lists the parameters specific to the Service SSH engine.
non-snmp-traffic-inspection Inspects for non-SNMP traffic destined
for UDP port 161.
snmp-inspection {yes | no} Enables inspection of SNMP traffic:
specify-object-id—Enables
inspection of the SNMP Object
identifier:
object-id—Specifies to search
for the SNMP object identifier.
specify-community-name—Enables i
nspection of the SNMP community
name:
community-name—Specifies
to search for the SNMP
community name (SNMP
password).
object-id
community-name
TableB-29 Service SNMP Engine Parameters (continued)
Parameter Description Value
TableB-30 Service SSH Engine Parameters
Parameter Description Value
length-type Inspects for one of the following SSH length types:
key-length—Enables inspection of the length of the
SSH key:
length—Specifies that keys larger than this fire the
RSAREF overflow.
user-length—Enables user length SSH inspection:
length—Specifies that keys larger than this fire the
RSAREF overflow.
0 to 65535
service-ports Specifies a comma-separated list of ports or port ranges
where the target service resides.
0 to 65535
1
a-b[,c-d]
specify-packet-depth
{yes | no}
(Optional) Enables packet depth:
packet-depth—Specifies the number of packets to
watch before determining the session key was missed.
0 to 65535