Chapter19 Intrusion Prevention System
Import Signatures
19-40
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Welcome to the IPS Signature Import Wizard
This window summarizes the tasks that you perform as you go throug h the IPS
Signature Import wizard.
Click Next to begin.
Signature Definition File (SDF) and Signature Selection
Click Browse, and navigate to the SDF that you saved on your PC. When the path
to the file is visible in the field, click Next to continue.
Signature Filter
The router may not have enough memory to use all signature s in the SDF. This
screen allows you to build a set of criteria that IPS uses to filter the signatures so
that the router only loads the ones appropriate for the network on which it is
running.
In the Category list, select the type of criteria that you want to specify, such as
OS, Service, or Attack. Then in the Value column, select the value for that
category. The following example shows a list of three criteria. Click More to add
a line. Click Fewer to remove the last line that you entered.
The read-only fields in the bottom part of the screens show the amount of memory
required for the signatures that meet the criteria that you entered, and th e amount
of memory available on the router. If the amount of memory required to load the
signatures that meet the criteria that you specified is greater than the available
memory on the router, use the Fewer button to remove criteria.
You are able to view the signatures that match the criteria that you selected in the
next screen.
Category Value
OS General
Service Telnet
Attack Adware/Spyware