Chapter19 Intrusion Prevention System
Import Signatures
19-42
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Signatures
This window lets you view the configured IPS signatures on the router. You can
add customized signatures, or import signatures from Cisc o.com-downloaded
Signature Definition Files (SDF). You can also edit, delete, enable, and disable
signatures.
IPS is shipped with an SDF that contains a number of signatures that your ro uter
can accommodate. To learn more about the SDF shipped with IPS, and how to
have IPS use it, click IPS-Supplied Signature Definition Files.

Signature Tree

The signature tree enables you to filter the signatu re list on the right according to
the type of signature that you want to view. First choose the branch for the general
type of signature that you want to display. The signature list displays the
configured signatures for the type that you chose. If a p lus (+) sign appears to the
left of the branch, there are subcategories that you can use to refine the filter. Click
on the + sign to expand the branch and then select the signature su bcategory that
you want to display. If the signature list is empty, there are no configured
signatures available for that type.
Example: If you want to display all attack signatures, click the Attack branch
folder. If you want to see the subcategories that you can use to filter the display
of attack signatures, click the + sign next to the Attack folder. If you want to see
Denial of Service (DoS) signatures, click the DoS folder.

Total [

n

] New [

n

] Deleted [

n

]

This text gives you the count of new signatures and deleted signatures.

Select All

Click to select all signatures in the list.
Add
Click Add if you want to do any of the following:
CloneThe clone option is enabled if one signature is selected that does not
belong to a hardcoded engine. It is disabled if the signa ture uses one of the
IOS hardcoded engines.