Chapter19 Intrusion Prevention System
Import Signatures
19-46
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08

Apply Changes button

Click to deliver newly imported signatures, signature edits, and newly enabled or
disabled signatures to the router. When the changes are applied, the yellow Wait
icon is removed from the ! column.

Discard Changes button

Click to discard accumulated changes.
Assign Actions
The window contains the actions that can be taken upon sign ature match.
Available actions depend on the signature, but the most common actions are listed
below:
alarmGenerate an alarm.
denyAttackerInlinecreates an ACL that denies all traffic from the IP
address that is considered the source o f the attack by the IOS IPS system.
denyFlowInlinecreates an ACL that denies all traffic from the IP address
that is considered the source of the attack that belongs to the 5-tuple (src ip,
src port, dst ip, dst port and l4 protocol). denyFlowInline is more granula r
than denyAttackerInline.
dropDrop the packet.
resetReset the connection.
Import Signatures
Use this window to import signatures from an SDF on your PC. The information
in this window tells you which signatures are available from the SDF, and which
of them are already deployed on your router.
Importing signatures is a two-step process. In Step 1, performed in the upper part
of the window, you choose the signatures that you want to import. In Step 2,
performed in the lower part of the window, you choose whether to merge these
signatures with the signatures that are already configured on the router, or to
replace the signatures on the router with the signatures that you are importing.