Contents
ix
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Monitoring Events
8-38
Displaying Events
8-38
Clearing Events from Event Store
8-41
CHAPTER
9
Configuring Anomaly Detection
9-1
Anomaly Detection Notes and Caveats
9-1
Understanding Security Policies
9-2
Understanding Anomaly Detection
9-2
Understanding Worms
9-2
Anomaly Detection Modes
9-3
Anomaly Detection Zones
9-4
Anomaly Detection Configuration Sequence
9-5
Anomaly Detection Signatures
9-6
Enabling Anomaly Detection
9-8
Working With Anomaly Detection Policies
9-8
Configuring Anomaly Detection Operational Settings
9-10
Configuring the Internal Zone
9-11
Understanding the Internal Zone
9-12
Configuring the Internal Zone
9-12
Configuring TCP Protocol for the Internal Zone
9-13
Configuring UDP Protocol for the Internal Zone
9-15
Configuring Other Protocols for the Internal Zone
9-18
Configuring the Illegal Zone
9-20
Understanding the Illegal Zone
9-20
Configuring the Illegal Zone
9-20
Configuring TCP Protocol for the Illegal Zone
9-21
Configuring UDP Protocol for the Illegal Zone
9-24
Configuring Other Protocols for the Illegal Zone
9-26
Configuring the External Zone
9-28
Understanding the External Zone
9-28
Configuring the External Zone
9-28
Configuring TCP Protocol for the External Zone
9-29
Configuring UDP Protocol for the External Zone
9-32
Configuring Other Protocols for the External Zone
9-34
Configuring Learning Accept Mode
9-36
The KB and Histograms
9-36
Configuring Learning Accept Mode
9-38
Working With KB Files
9-40