Chapter19 Intrusion Prevention System
Global Settings
19-52
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Notification Method StatusConfigured SDF Locations
A signature location is an URL that provides a path to an SDF. To find an SDF,
the router attempts to contact the first location in the list. If it fails, it tries each
subsequent location in turn, until it finds an SDF.
Add Button
Click to add an URL to the list.
Edit Button
Click to edit a selected location.
Syslog If Enabled, then notifications are sent to the syslog server specified in System
Properties.
SDEE Security Device Event Exchange. If Enabled, SDEE events are generated.
SDEE Events The number of SDEE events to store in the routers buffer.
SDEE Subscription The number of concurrent SDEE subscriptions.
Engine Options The engine options are the following:
Fail ClosedBy default, while IOS compiles a new signature for a particular
engine, it allows packets to pass through without scanning for the
corresponding engine. When enabled, this option makes IOS drop pa ckets
during the compilation process.
Use Built-in Signatures (as backup)If IPS does not find or fails to load
signatures from the specified location(s), it can use the IOS built-in
signatures to enable IPS. This option is enabled by default.
Deny Action on IPS InterfaceRecommended when router is performing
load balancing. When enabled, this option causes IPS to enable ACLs on IPS
interfaces instead of enabling them on the interfaces from which attack
traffic came.
Shun Events This category uses the Shun Time parameter. Shun Time is the amount of time
that shun actions are to be in effect.