Chapter19 Intrusion Prevention System
SDEE Messages
19-54
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08

Enable Deny Action on IPS interface

This option is applicable if signature actions are configured to
"denyAttackerInline" or "denyFlowInline". By default, IPS applies ACLs to the
interfaces from which attack traffic came, and not to IPS interfaces. Enabling this
option causes IPS to apply the ACLs directly to the IPS interfaces, and not to the
interfaces that originally received the attack traffic. If the router is not performing
load balancing this setting should not be enabled. If the router is performing load
balancing, it is recommended that you enable this setting.

Shun Time

Set the number of minutes that shun actions are to be in effect. The default value
is 30 minutes.
SDEE Messages
This window lists the SDEE messages received by the router. SDEE messages are
generated when there are changes to IPS configuration.

Select By:

All SDEE error, status, and alert messages are shown.
ErrorOnly SDEE error messages are shown.
StatusOnly SDEE status messages are shown.
AlertsOnly SDEE alert messages are shown.
Type
Types are: Error, and Status. Click SDEE Message Text to see possible SDEE
messages

Time

The time the message is received.