19-33
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter19 Intrusion Prevention Sy stem
IPS Rules
The location of the Signature Definition File (SDF).
The use case scenario illustrates a configuration in which an IPS rule is used.
Once you create the IPS rule and deliver the configuration to the router, you can
modify the rule by clicking the Edit IPS Rule tab.
Click the Launch IPS Rule Wizard button to begin.
Welcome to the IPS Rule Configuration Wizard
This window provides a summary of the tasks that you perform w hen you
complete the IPS Rule wizard.
Click Next to begin configuring an IPS rule.
Select Interfaces
Select the interfaces on which you want to apply the IPS rule by specifying
whether the rule is to be applied to inbound traffic or outbound traffic. If you
check both the inbound and the outbound boxes the rule applies to traffic flowing
in both directions.
For example, the following selections apply IPS on inbound traffic on the BRI 0
interface, and both traffic directions on the FastEthernet 0 interface.
SDF Location
IPS examines traffic by comparing it against signatures contained in a Signature
Definition File (SDF). The SDF can be located in router flash or located on a
remote system that the router can reach. You can specify multiple SDF locations
so that if the router is not able to contact the first location, it can attempt to contact
other locations until it obtains an SDF.
Interface Name Inbound Outbound
BRI 0 Check
FastEthernet 0 Check Check