Chapter19 Intrusion Prevention System
Import Signatures
19-44
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
SDFs are available from Cisco. Click the following URL to download an SDF
from Cisco.com:
http://www.cisco.com/cgi-bin/tablebuild.pl/ios-sigup
Cisco maintains an alert center that provides information on emerging threats. See
Cisco Intrusion Prevention Alert Center for more information
Summary/Details Button
Use this button to display or hide the signatures marked for deletion.
Signature List
The signature list displays the signatures retrieved from the router, and any
signatures added from an SDF. The list can be filtered using the selection controls.
Enabled Enabled signatures are indicated with a green icon. If enabled, the actions specified
when the signature is detected is carried out.
Disabled signatures are indicated with a red icon. If disabled, the actions are disabled
and are not be carried out.
Alert (!) This column may contain the yellow Wait icon. This icon indicates new signatures that
have not been delivered to the router or modified signatures that have not been delivered
to the router.
Sig ID The numerical signature ID. For example, the sigID for I CMP Echo Reply is 2000.
SubSig ID The subsignature ID.
Name The name of the signature, for example ICMP Echo Reply.
Action The action to take when the signature is detected.
Filter An ACL associated with the corresponding signature.
Severity The severity level of the event. Severity levels are informational, low, medium, and high
Engine The engine to which the signature belongs.