Glossary
GL-8
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
F
fail closed
Blocks traffic on the device after a hardware failure.
fail open
Lets traffic pass through the device after a hardware failure.
false negative
A signature is not fired when offending traffic is detected.
false positive
Normal traffic or a benign action causes a signature to fire.
Fast Ethernet
Any of a number of 100-Mbps Ethernet specifications. Fast Ethernet offers a speed increase 10 times
that of the 10BaseT Ethernet specification while preserving such qualities as frame format, MAC
mechanisms, and MTU. Such similarities allow the use of existing 10BaseT applications and network
management tools on Fast Ethernet networks. Based on an extension to the IEE E 802.3 specification.
Fast flux
Fast flux is a DNS technique used by Botnets to hide phishing and malware delivery sites behind an
ever-changing network of compromised hosts acting as proxies. It can also refer to the combination of
peer-to-peer networking, distributed command and control, web-based load balancing and proxy
redirection used to make malware networks more resistant to discovery and counter-measures. The
Storm Worm is one of the recent malware variants to make use of this technique.
firewall
Router or access server, or several routers or access servers, designated as a buffer between any
connected public networks and a private network. A firewall router uses access lists and other methods
to ensure the security of the private network.
Flood engine
Detects ICMP and UDP floods directed at hosts and networks.
flooding
Traffic passing technique used by switches and bridges in which traffic received on an interface is sent
out all the interfaces of that device except the interface on which the information was received
originally.
forwarding
Process of sending a frame toward its ultimate destination by way of an internetworking device.
fragment
Piece of a larger packet that has been broken down to smaller units.
fragmentation
Process of breaking a packet into smaller units when transmitting over a network medium that cannot
support the original size of the packet.
Fragment
Reassembly
Processor
A processor in the IPS. Reassembles fragmented IP datagrams. It is also responsible for normalization
of IP fragments when the sensor is in inline mode.
FTP
File Transfer Protocol. Application protocol, part of the TCP/IP protocol stack, used for transferring
files between network nodes. FTP is defined in RFC 959.
FTP server
File Transfer Protocol server. A server that uses the FTP protocol for transferring files between network
nodes.
full duplex
Capability for simultaneous data transmission between a sending station and a receiving station.