Installing and Using Cisco Intrusion Prevention System Device Manager 6.0
Index

Table Of Contents

Numerics - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - Z

Index

Numerics

4GE bypass interface card

configuration restrictions 3-11

described 3-11

802.1q encapsulation

VLAN groups 3-14

A

accessing IPS software 13-2

access list misconfiguration C-26

ACLs

described 9-2

Post-Block 9-20, 9-21

Pre-Block 9-20, 9-21

Active Host Blocks pane

configuring 9-32, 12-4

described 9-31, 12-2

field descriptions 9-31, 12-3

user roles 9-31, 12-2

active update bulletin subscription 13-15

ad0 pane

default 7-10

described 7-10

tabs 7-10

Add Active Host Block dialog box field descriptions 9-32, 12-3

Add Allowed Host dialog box

field descriptions 2-12

user roles 2-11

Add Authorized Key dialog box

field descriptions 2-14

user roles 2-14

Add Blocking Device dialog box

field descriptions 9-17

user roles 9-17

Add Cat 6K Blocking Device Interface dialog box

field descriptions 9-26

user roles 9-25

Add Configured OS Map dialog box

field descriptions 6-28

user roles 6-25

Add Destination Port dialog box field descriptions 7-16, 7-17, 7-24, 7-25, 7-32, 7-33

Add Device Login Profile dialog box

field descriptions 9-15

user roles 9-14

Add Event Action Filter dialog box

field descriptions 6-20

user roles 6-19

Add Event Action Override dialog box

field descriptions 6-14

user roles 6-13

Add Event Variable dialog box

field descriptions 6-31

user roles 6-30

Add External Product Interface dialog box

field descriptions 10-5

user roles 10-1

Add Histogram dialog box field descriptions 7-16, 7-17, 7-19, 7-25, 7-26, 7-27, 7-32, 7-33, 7-34

adding

active host blocks 9-32, 12-4

a host never to be blocked 9-11

anomaly detection policies 7-9

event action filters 6-23

event action overrides 6-16

event action rules policies 6-12

event variables 6-31

external product interfaces 10-8

network blocks 9-34, 12-6

OS maps 6-29

signature definition policies 5-2

signatures 5-14

signature variables 5-56

target value ratings 6-18

virtual sensors 4-5

Add Inline VLAN Pair dialog box

field descriptions 3-21

user roles 3-20

Add Interface Pair dialog box

field descriptions 3-19

user roles 3-19

Add IP Logging dialog box

field descriptions 12-21

user roles 12-20

Add Known Host Key dialog box

field descriptions 2-16

user roles 2-16

Add Master Blocking Sensor dialog box

field descriptions 9-29

user roles 9-28

Add Network Block dialog box

field descriptions 9-34

user roles 9-34

Add Never Block Address dialog box

field descriptions 9-10

user roles 9-7

Add Policy dialog box

field descriptions 5-2, 6-12, 7-8

user roles 5-2, 6-11, 7-8

Add Posture ACL dialog box

field descriptions 10-7

user roles 10-1

Add Protocol Number dialog box field descriptions 7-18, 7-26, 7-34

Add Rate Limit dialog box

field descriptions 9-13

user roles 9-12

Address Resolution Protocol see ARP

Add Router Blocking Device Interface dialog box

field descriptions 9-23

user roles 9-20

Add Signature dialog box

field descriptions 5-7

user roles 5-4

Add Signature Variable dialog box

field descriptions 5-56

user roles 5-55

Add SNMP Trap Destination dialog box

field descriptions 8-4

user roles 8-3

Add Target Value Rating dialog box

field descriptions 6-18

user roles 6-17

Add Trusted Host dialog box

field descriptions 2-20

user roles 2-20

Add User dialog box

field descriptions 2-35

user roles 2-33

Add Virtual Sensor dialog box

described 4-5

field descriptions 4-5

Add VLAN Group dialog box

field descriptions 3-24

user roles 3-23

Administrator privileges A-26

Advanced Alert Behavior Wizard

Alert Dynamic Response Fire All window field descriptions 5-42

Alert Dynamic Response Fire Once window field descriptions 5-42

Alert Dynamic Response Summary window field descriptions 5-41

Alert Summarization window field descriptions 5-41

Event Count and Interval window field descriptions 5-40

Global Summarization window field descriptions 5-42

advisory for cryptographic products 1-1

AIC engine

AIC FTP B-7

AIC HTTP B-7

described 5-60, B-7

features B-7

signatures (example) 5-68

AIC FTP engine parameters (table) B-9

AIC HTTP engine parameters (table) B-8

AIC policy configuration 5-67

AIC policy enforcement

default configuration 5-61, B-7

described 5-61, B-7

sensor oversubscription 5-61, B-7

AIM-IPS

initializing 1-33

setup command 1-33

system image installation 14-48

time sources 2-24, C-15

verifying installation C-69

AIP-SSM

Bypass mode 3-27

initializing 1-21

password recovery 2-8, C-11

recovering C-67

reimaging 14-51

resetting C-67

setup command 1-21

system image installation 14-51

time sources 2-24, C-15

Alarm Channel described 6-5, A-24

alert frequency

aggregation 5-21

configuring 5-21

controlling 5-21

modes B-5

alert profile in Home window 1-2

alert summary in Home window 1-2

Allowed Hosts pane

configuring 2-12

described 2-11

alternate TCP reset interface configuration restrictions 3-9

Analysis Engine

busy C-23

described 4-1

global variables 4-7

verify it is running C-20

virtual sensors 4-1

Analysis Engine busy

error messages C-23

IDM exits C-58

anomaly detection

asymmetric environment 7-2

caution 7-2

configuration sequence 7-4

default configuration (example) 7-4

described 7-2

detect mode 7-3

disabling C-19

event actions 7-6, B-43

inactive mode 7-3

learning accept mode 7-3

learning process 7-3

limiting false positives 7-12

protocols 7-2

signatures (table) 7-6, B-44

worm attacks 7-12

worms 7-2

zones 7-4

Anomaly Detection pane

described 7-8

field descriptions 7-8, 7-39, 12-12

user roles 7-8, 7-39, 12-12

anomaly detection policies

ad0 7-8

adding 7-9

cloning 7-9

default policy 7-8

deleting 7-9

user roles 7-8

appliances

application partition image 14-13

GRUB menu 2-5, C-8

initializing 1-6

password recovery 2-5, C-8

recovering the software image 14-29

terminal servers

described 14-16

setting up 14-16

time sources 2-23, C-14

upgrading the recovery partition 14-6

Application Inspection and Control see AIC

application partition

described A-3

image recovery 14-13

application policy enforcement described 5-61, B-7

applications in XML format A-2

applying software updates C-53

ARC

ACLs 9-21, A-12

authentication A-13

blocking

application 9-1

connection-based A-16

not occurring for signature C-42

unconditional blocking A-16

block response A-12

Catalyst 6000 series switch

VACL commands A-18

VACLs A-18

Catalyst switches

VACLs A-15

VLANs A-15

checking status 9-3, 9-4, 12-7

described A-2

design 9-2

device access issues C-39

enabling SSH C-42

features A-12

firewalls

AAA A-17

connection blocking A-17

NAT A-17

network blocking A-17

postblock ACL A-15

preblock ACL A-15

shun command A-17

TACACS+ A-17

formerly Network Access Controller 9-3

functions 9-1, A-11

illustration A-11

inactive state C-38

interfaces A-13

maintaining states A-15

managed devices 9-7

master blocking sensors A-13

maximum blocks 9-2

misconfigured master blocking sensor C-43

nac.shun.txt file A-15

NAT addressing A-14

number of blocks A-14

postblock ACL A-15

preblock ACL A-15

prerequisites 9-5

rate limiting 9-4, 12-7

responsibilities A-11

single point of control A-14

SSH A-12

supported devices 9-6, A-14

Telnet A-12

troubleshooting C-36

VACLs A-12

verifying device interfaces C-41

verifying status C-37

ARP

Layer 2 signatures B-10

protocol B-10

ARP spoof tools

dsniff B-10

ettercap B-10

Assign Actions dialog box field descriptions 5-11

assigning actions to signatures 5-18

asymmetric environment and anomaly detection 7-2

asymmetric traffic and disabling anomaly detection C-19

Atomic ARP engine

described B-10

parameters (table) B-10

Atomic IP engine

described B-10

parameters (table) B-10

Atomic IPv6 engine

described B-11

Neighborhood Discovery protocol B-11

signatures B-11

signatures (table) B-12

attack relevance rating

calculating risk rating 6-3

described 6-3, 6-25

Attack Response Controller

described A-2

formerly known as Network Access Controller A-2

See ARC

attack severity rating

calculating risk rating 6-3

described 6-3

authenticated NTP 2-30

AuthenticationApp

authenticating users A-20

described A-3

login attempt limit A-19

method A-19

responsibilities A-19

secure communications A-20

sensor configuration A-19

Authorized Keys pane

configuring 2-14

described 2-14

field descriptions 2-14

RSA authentication 2-14

RSA key generation tool 2-15

automatic updates

Cisco.com 11-1

servers

FTP 11-1

SCP 11-1

troubleshooting C-54

automatic upgrade

examples 14-11

required information 14-7

autonegotiation and hardware bypass 3-12

Auto Update pane

configuring 11-3

described 11-1

field descriptions 11-2

UNIX-style directory listings 11-2

user roles 11-1

auto-upgrade-option command 14-7

B

backing up

configuration C-2

current configuration C-4

BackOrifice 2000 see BO2K

BackOrifice see BO

blocking

described 9-1

disabling 9-8

master blocking sensor 9-28

necessary information 9-3

not occurring for signature C-42

prerequisites 9-5

supported devices 9-6

types 9-2

Blocking Devices pane

configuring 9-18

described 9-17

field descriptions 9-17

ssh host-key command 9-18

Blocking Properties pane

adding a host never to be blocked 9-11

configuring 9-10

described 9-7

field descriptions 9-8

BO

described B-46

Trojans B-46

BO2K

described B-46

Trojans B-46

bootloader

explaining 14-33

upgrading 14-33

Bypass mode

AIP-SSM 3-27

described 3-26

Bypass pane

field descriptions 3-26

user roles 3-26

C

calculating risk rating

attack relevance rating 6-3

attack severity rating 6-3

promiscuous delta 6-3

signature fidelity rating 6-2

target value rating 6-3

watch list rating 6-3

cannot access sensor C-24

Cat 6K Blocking Device Interfaces pane

configuring 9-26

described 9-25

field descriptions 9-26

certificates

displaying 2-22

generating 2-22

Internet Explorer 1-48

changing Microsoft IIS to UNIX-style directory listings 11-2

changing the memory

Java Plug-in on Linux 1-43, C-57

Java Plug-in on Solaris 1-43, C-57

Java Plug-in on Windows 1-42, C-56

cidDump and obtaining information C-91

CIDEE

defined A-32

example A-32

IPS extensions A-32

protocol A-32

supported IPS events A-32

Cisco.com

accessing software 13-2

Active Update Bulletins 13-15

downloading software 13-1

IPS software 13-1

software downloads 13-1

Cisco IOS and rate limiting 9-4, 12-7

cisco-security-agents-mc-settings command 10-7

Cisco Security Center

described 13-16

URL 13-16

Cisco Services for IPS

service contract 1-51, 13-10

supported products 1-51, 13-10

clear events command 2-28, 2-33, C-17, C-91

clearing

events 2-33, C-91

statistics C-77

clear password command 2-7, 2-8, C-10, C-11

CLI described A-3, A-26

clock set command 2-32

Clone Policy dialog box

field descriptions 5-2, 6-12, 7-8

user roles 5-2, 6-11, 7-8

Clone Signature dialog box

field descriptions 5-7

user roles 5-4

cloning

anomaly detection policies 7-9

event action rules policies 6-12

signature definition policies 5-2

signatures 5-16

command and control interfaces

described 3-2

list 3-2

commands

auto-upgrade-option 14-7

cisco-security-agents-mc-settings 10-7

clear events 2-28, 2-33, C-17, C-91

clear password 2-7, 2-8, C-10, C-11

clock set 2-32

copy backup-config C-3

copy current-config C-3

copy license-key 13-13

debug module-boot C-67

downgrade 14-12

hw-module module 1 reset C-67

hw-module module slot_number password-reset 2-8, C-11

setup 1-3, 1-6, 1-14, 1-21, 1-28, 1-33, 2-1

show events C-88

show inventory C-69

show module 1 details C-66

show settings 2-10, C-13

show statistics C-76

show statistics virtual-sensor C-23, C-76

show tech-support C-70

show version C-73

upgrade 14-3, 14-6

Compare Knowledge Bases dialog box field descriptions 7-41, 12-14

comparing KBs 7-42, 12-15

configuration files

backing up C-2

merging C-2

configuration restrictions

alternate TCP reset interface 3-9

inline interface pairs 3-9

inline VLAN pairs 3-9

interfaces 3-9

physical interfaces 3-9

VLAN groups 3-10

Configure Summertime dialog box field descriptions 2-26

configuring

active host blocks 9-32, 12-4

AIC policy parameters 5-67

allowed hosts 2-12

application policy 5-68

authorized keys 2-14

automatic upgrades 14-9

blocking devices 9-18

blocking properties 9-10

Cat 6K blocking device interfaces 9-26

CSA MC support for IPS interfaces 10-4

device login profiles 9-15

event action filters 6-23

events 6-35

event variables 6-31

external zone 7-35

general settings 6-33

illegal zone 7-27

interface pairs 3-19

interfaces 3-17

interfaces (sequence) 3-8

internal zone 7-19

IP fragment reassembly signatures 5-72

IP logging 12-21

known host keys 2-16

learning accept mode 7-13

maintenance partition

IDSM-2 (Catalyst software) 14-39

IDSM-2 (Cisco IOS software) 14-43

master blocking sensor 9-29

network blocks 9-34, 12-6

NTP servers 2-29

operation settings 7-11

OS maps 6-29

rate limiting 9-13, 12-9

rate limiting devices 9-18

router blocking device interfaces 9-23

sensor to use NTP 2-30

SNMP 8-2

SNMP traps 8-4

target value ratings 6-18

TCP fragment reassembly parameters 5-78

time 2-27

traffic flow notifications 3-28

trusted hosts 2-20

upgrades 14-4

users 2-35

VLAN groups 3-24

VLAN pairs 3-22

control transactions

characteristics A-7

request types A-7

cookies and IDM 1-47

copy backup-config command C-3

copy current-config command C-3

copy license-key command 13-13

correcting time on the sensor 2-28, C-17

creating

custom signatures

not using signature engines 5-29

Service HTTP 5-52

String TCP 5-50

using signature engines 5-28

Meta signatures 5-24

Post-Block VACLs 9-25

Pre-Block VACLs 9-25

service account C-5

cryptographic account

Encryption Software Export Distribution Authorization from 13-2

obtaining 13-2

cryptographic products and IDM 1-1

CSA MC

configuring IPS interfaces 10-4

host posture events 10-2, 10-4

quarantined IP address events 10-2

supporting IPS interfaces 10-4

CtlTransSource

described A-2, A-10

illustration A-10

current configuration backup C-2

current KB settings 7-43, 12-16

custom signatures

described 5-4

Meta signature 5-24

Custom Signature Wizard

Alert Response window field descriptions 5-39

Atomic IP Engine Parameters window field descriptions 5-32

described 5-27

ICMP Traffic Type window field descriptions 5-38

Inspect Data window field descriptions 5-39

MSRPC Engine Parameters window field descriptions 5-34

no signature engine sequence 5-29

Protocol Type window field descriptions 5-31

Service HTTP Engine Parameters window field descriptions 5-33

Service RPC Engine Parameters window field descriptions 5-34

Service Type window field descriptions 5-39

signature engine sequence 5-28

Signature Identification window field descriptions 5-31

State Engine Parameters window field descriptions 5-35

String ICMP Engine Parameters window field descriptions 5-35

String TCP Engine Parameters window field descriptions 5-36

String UDP Engine Parameters window field descriptions 5-37

Sweep Engine Parameters window field descriptions 5-37

TCP Sweep Type window field descriptions 5-39

TCP Traffic Type window field descriptions 5-38

UDP Sweep Type window field descriptions 5-38

UDP Traffic Type window field descriptions 5-38

user roles 5-27

Welcome window field descriptions 5-31

D

data structure examples A-7

DDoS

protocols B-45

Stacheldraht B-45

TFN B-45

debug logging enabling C-45

debug-module-boot command C-67

default KB filename 7-13

default policies

ad0 7-8

rules0 6-11

sig0 5-2

defaults restoring 11-4

default virtual sensor vs0 4-2

deleting

anomaly detection policies 7-9

event action filters 6-23

event action overrides 6-16

event action rules policies 6-12

event variables 6-31

imported OS values 6-38, 12-11

KBs 7-43, 12-16

learned OS values 6-37, 12-10

OS maps 6-29

signature definition policies 5-2

signature variables 5-56

target value ratings 6-18

virtual sensors 4-5

Denial of Service see DoS

denied attackers

clearing list 12-2

hit count 12-1

resetting hit counts 12-2

Denied Attackers pane

described 12-1

field descriptions 12-1

user roles 12-1

using 12-2

detect mode and anomaly detection 7-3

device access issues C-39

device information in the Home window 1-2

Device Login Profiles pane

configuring 9-15

described 9-14

field descriptions 9-15

Diagnostics Report pane

button functions 11-9

described 11-8

user roles 11-8

using 11-9

diagnostics reports 11-9

disabling

anomaly detection C-19

blocking 9-8

interfaces 3-17

password recovery 2-9, C-12

disaster recovery C-6

displaying

events C-89

password recovery setting 2-10, C-13

statistics C-77

tech support information C-71

version C-73

Distributed Denial of Service see DDoS

DoS tools (stick) B-5

downgrade command 14-12

downgrading sensors 14-12

downloading

KBs 7-45, 12-18

software 13-1

Download Knowledge Base From Sensor dialog box

described 7-44, 12-17

user roles 7-44, 12-17

duplicate IP addresses C-27

E

Edit Allowed Host dialog box

field definitions 2-12

user roles 2-11

Edit Authorized Key dialog box

field definitions 2-14

user roles 2-14

Edit Blocking Device dialog box

field descriptions 9-17

user roles 9-17

Edit Cat 6K Blocking Device Interface dialog box

field descriptions 9-26

user roles 9-25

Edit Configured OS Map dialog box

field descriptions 6-28

user roles 6-25

Edit Destination Port dialog box field descriptions 7-16, 7-17, 7-24, 7-32, 7-33

Edit Device Login Profile dialog box

field descriptions 9-15

user roles 9-14

Edit Event Action Filter dialog box

field descriptions 6-20

user roles 6-19

Edit Event Action Override dialog box

field descriptions 6-14

user roles 6-13

Edit Event Variable dialog box

field descriptions 6-31

user roles 6-30

Edit External Product Interface dialog box

field descriptions 10-5

user roles 10-1

Edit Histogram dialog box field descriptions 7-16, 7-17, 7-19, 7-25, 7-27, 7-32, 7-33, 7-34

editing

event action filters 6-23

event action overrides 6-16

event variables 6-31

interfaces 3-18

OS maps 6-29

signatures 5-17

signature variables 5-56

target value ratings 6-18

virtual sensors 4-5

Edit Inline VLAN Pair dialog box

field descriptions 3-21

user roles 3-20

Edit Interface dialog box

field descriptions 3-16

user roles 3-15

Edit Interface Pair dialog box

field descriptions 3-19

user roles 3-19

Edit IP Logging dialog box

field descriptions 12-21

user roles 12-20

Edit Known Host Key dialog box

field descriptions 2-16

user roles 2-16

Edit Master Blocking Sensor dialog box

field descriptions 9-29

user roles 9-28

Edit Never Block Address dialog box

field descriptions 9-10

user roles 9-7

Edit Posture ACL dialog box field descriptions 10-7

Edit Protocol Number dialog box field descriptions 7-26

Edit Router Blocking Device Interface dialog box

field descriptions 9-23

user roles 9-20

Edit Signature dialog box

field descriptions 5-7

user roles 5-4

Edit Signature Variable dialog box

field descriptions 5-56

user roles 5-55

Edit SNMP Trap Destination dialog box

field descriptions 8-4

user roles 8-3

Edit Target Value Rating dialog box

field descriptions 6-18

user roles 6-17

Edit User dialog box

field descriptions 2-35

user roles 2-33

Edit Virtual Sensor dialog box

field descriptions 4-5

user roles 4-4

Edit VLAN Group dialog box

field descriptions 3-24

user roles 3-23

enabling

debug logging C-45

event action filters 6-23

event action overrides 6-16

interfaces 3-17

Encryption Software Export Distribution Authorization form

cryptographic account 13-2

described 13-2

error message Analysis Engine is busy C-23

evAlert A-8

event action filters

adding 6-23

configuring 6-23

deleting 6-23

described 6-4

editing 6-23

enabling 6-23

Event Action Filters tab

configuring 6-23

described 6-19

field descriptions 6-19

event action overrides

adding 6-16

deleting 6-16

described 6-4

editing 6-16

enabling 6-16

Event Action Overrides tab

field descriptions 6-14

user roles 6-13

event action rules

default policy 6-11

example 6-10

functions 6-2

rules0 6-11

understanding 6-2

Event Action Rules pane

described 6-11

field descriptions 6-12

user roles 6-11

event action rules policies

adding 6-12

cloning 6-12

deleting 6-12

event actions

described 6-8

table 6-8

events

display configuration 6-35

displaying C-89

host posture 10-2

quarantined IP address 10-2

Events pane

configuring 6-35

described 6-34

field descriptions 6-34

Event Store

clearing events 2-28, C-17

data structures A-7

described A-2

examples A-6

responsibilities A-6

timestamp A-6

event types C-87

event variables

adding 6-31

configuring 6-31

deleting 6-31

editing 6-31

example 6-30

Event Variables tab

configuring 6-31

described 6-30

field descriptions 6-31

Event Viewer window field descriptions 6-35

evError A-8

evLogTransaction A-8

evShunRqst A-8

evStatus A-8

external product interfaces

adding 10-8

described 10-1

issues 10-3, C-21

troubleshooting 10-11, C-22

External Product Interfaces pane

field descriptions 10-4

user roles 10-1

external zone

configuring 7-35

protocols 7-31

user roles 7-31

External Zone tab

described 7-31

tabs 7-31

user roles 7-31

F

fail-over testing 3-11

false positives described 5-3

files

IDSM-2 password recovery 2-7, C-10

upgrade 14-3

finding the serial number C-69

Flood engine described B-12

Flood Host engine parameters (table) B-12

Flood Net engine parameters (table) B-13

FTP servers supported 14-2

G

general settings

configuring 6-33

described 6-32

General Settings tab

configuring 6-33

described 6-32

field descriptions 6-33

user roles 6-32

General tab

described 7-15, 7-23

enabling zones 7-15, 7-23

field descriptions 7-15, 7-23

generating diagnostics reports 11-9

Global Variables pane

described 4-7

field definitions 4-7

user roles 4-7

GRUB menu for password recovery 2-5, C-8

H

H.225.0 protocol B-23

H.323 protocol B-23

hardware bypass

autonegotiation 3-12

configuration restrictions 3-11

fail-over 3-11

IPS-4260 3-11

IPS 4270-20 3-11

supported configurations 3-11

with software bypass 3-11

Home window

auto refresh 1-2

described 1-2

host posture events

CSA MC 10-4

described 10-2

HTTP/HTTPS supported servers 14-2

HTTP deobfuscation

ASCII normalization 5-52, B-25

described 5-52, B-25

hw-module module 1 reset command C-67

hw-module module slot_number password-reset command 2-8, C-11

I

IDAPI

communications A-3, A-28

described A-3

functions A-28

illustration A-28

responsibilities A-28

IDCONF

described A-31

example A-31

RDEP2 A-31

XML A-31

IDIOM

defined A-30

messages A-30

IDM

advisory 1-1

Analysis Engine is busy C-58

certificates 1-47, 2-18

cookies 1-47

cryptographic products 1-1

described 1-1, 1-44, 1-45

GUI 1-1

Java Plug-in 1-42, C-56

logging in 1-44, 1-45

memory 1-42, C-56

prerequisites 1-44

Signature Wizard unsupported signature engines5-27, 5-43

TLS and SSL 1-47, 2-19

user interface 1-1

validating certificates 1-48

web browsers 1-1, 1-44, 1-45

will not load C-57

IDS-4215

BIOS upgrade 14-20

installing system image 14-17

installing the system image 14-17

ROMMON upgrade 14-20

upgrading

BIOS 14-20

ROMMON 14-20

IDSM-2

command and control port C-64

configuring

maintenance partition (Catalyst software) 14-39

maintenance partition (Cisco IOS software) 14-43

initializing 1-14

installing

system image (Catalyst software) 14-36

system image (Cisco IOS software) 14-37

password recovery 2-7, C-10

password recovery image file 2-7, C-10

reimaging 14-36

setup command 1-14

supported configurations C-61

time sources 2-23, C-14

upgrading

maintenance partition (Catalyst software) 14-46

maintenance partition (Cisco IOS software) 14-47

illegal zone

configuring 7-27

user roles 7-23

Illegal Zone tab

described 7-23

user roles 7-23

Imported OS pane

clearing 6-38, 12-11

described 6-37, 12-11

field descriptions 6-38, 12-11

imported OS values

clearing 6-38, 12-11

deleting 6-38, 12-11

user roles 6-37, 12-11

inactive mode and anomaly detection 7-3

initializing

AIM-IPS 1-33

AIP-SSM 1-21

appliances 1-6

IDSM-2 1-14

NM-CIDS 1-28

sensors 1-3, 2-1

verification 1-39

Inline Interface Pair mode

configuration restrictions 3-9

described 3-13

inline VLAN pair mode

configuration restrictions 3-9

described 3-13

supported sensors 3-13

installer major version described 13-6

installer minor version described 13-6

installing

AIM-IPS system image 14-48

license key 13-14

sensor license 1-53, 13-12

system image

AIP-SSM 14-51

IDS-4215 14-17

IDSM-2 (Catalyst software) 14-36

IDSM-2 (Cisco IOS software) 14-37

IPS-4240 14-21

IPS-4255 14-21

IPS-4260 14-25

IPS 4270-20 14-27

InterfaceApp described A-2

interface configuration sequence 3-8

interface pairs

configuring 3-19

described 3-19

Interface Pairs pane

configuring 3-19

described 3-19

field descriptions 3-19

interfaces

alternate TCP reset 3-2

command and control 3-2

configuration restrictions 3-9

configuring 3-17

described 3-1

disabling 3-17

editing 3-18

enabling 3-17

port numbers 3-1

sensing 3-2, 3-3

slot numbers 3-1

support (table) 3-4

TCP reset 3-7

VLAN groups 3-2

Interfaces pane

configuring 3-17

described 3-15

field descriptions 3-16

interface status and the Home window 1-2

internal zone

configuring 7-19

user roles 7-15

Internal Zone tab

described 7-15

user roles 7-15

Internet Explorer certificate validation 1-48

IP fragmentation described B-16

IP fragment reassembly

configuring 5-71

described 5-69

mode 5-71

parameters (table) 5-69

signatures 5-72

signatures (example) 5-72

signatures (table) 5-69

IP logging

described 5-79, 12-19

event actions 12-20

system performance 12-20

IP Logging pane

configuring 12-21

described 12-20

field descriptions 12-20

user roles 12-20

IP logs

circular buffer 12-20

states 12-19

TCP Dump 12-20

viewing 12-21

Wireshark 12-20

IPS

external communications A-29

internal communications A-28

IPS-4240

installing the system image 14-21

password recovery 2-6, C-9

reimaging 14-21

IPS-4255

installing the system image 14-21

password recovery 2-6, C-9

reimaging 14-21

IPS-4260

hardware bypass 3-11

installing the system image 14-25

reimaging 14-25

IPS 4270-20

hardware bypass 3-11

installing the system image 14-27

reimaging 14-27

IPS applications

summary A-33

table A-33

XML format A-2

IPS data

types A-7

XML document A-7

IPS events

evAlert A-8

evError A-8

evLogTransaction A-8

evShunRqst A-8

evStatus A-8

listed A-8

types A-8

IPS features

anomaly detection A-3

CSA collaboration A-3

enhanced password recovery A-3

passive OS fingerprinting A-3

signature policy virtualization A-3

threat rating A-3

IPS modules and time synchronization 2-25, C-16

IPS software

application list A-2

available files 13-1

configuring device parameters A-4

directory structure A-32

Linux OS A-1

new features A-3

obtaining 13-1

platform-dependent release examples 13-7

retrieving data A-4

security features A-4

tuning signatures A-4

updating A-4

user interaction A-4

versioning scheme 13-3

IPS software file names

major updates (illustration) 13-3

minor updates (illustration) 13-3

patch releases (illustration) 13-3

service packs (illustration) 13-3

IPv6 described B-11

J

Java Plug-in

Linux 1-43, C-57

Solaris 1-43, C-57

Windows 1-42, C-56

K

KBs

comparing 7-42, 12-15

default filename 7-13

deleting 7-43, 12-16

described 7-3

downloading 7-45, 12-18

histogram 7-12

initial baseline 7-3

learning accept mode 7-13

loading 7-43, 12-16

monitoring 7-40, 12-13

renaming 7-44, 12-17

saving 7-43, 12-16

scanner threshold 7-12

tree structure 7-12

uploading 7-46, 12-19

Knowledge Base see KB

Known Host Keys pane

configuring 2-16

described 2-16

field descriptions 2-16

L

Learned OS pane

clearing 6-37, 12-10

described 6-37, 12-10

field descriptions 6-37, 12-10

passive OS fingerprinting 6-37, 12-10

learned OS values

clearing 6-37, 12-10

deleting 6-37, 12-10

user roles 6-36, 12-10

learning accept mode

anomaly detection 7-3

configuring 7-13

user roles 7-13

Learning Accept Mode tab

described 7-13

field descriptions 7-13

user roles 7-13

license key

installing 13-14

status 1-50, 13-9

trial 1-50, 13-9

licensing

described 1-50, 13-9

IPS device serial number 1-50, 13-9

Licensing pane

configuring 1-53, 13-12

described 1-50, 13-9

field descriptions 1-52

user roles 1-50

limitations on concurrent CLI sessions 1-43

listings UNIX-style 11-2

loading KBs 7-43, 12-16

LogApp

described A-2, A-18

functions A-18

syslog messages A-19

logging in

IDM 1-44, 1-45

terminal servers 14-16

LOKI

described B-45

protocol B-45

loose connections on sensors C-22

M

MainApp

applications A-5

described A-2

host statistics A-5

responsibilities A-5

show version command A-5

maintenance partition

configuring

IDSM-2 (Catalyst software) 14-39

IDSM-2 (Cisco IOS software) 14-43

described A-3

major updates described 13-3

managing rate limiting 9-13, 12-9

manual block to bogus host C-42

master blocking sensor

described 9-28

not set up properly C-43

Master Blocking Sensor pane

configuring 9-29

described 9-28

field descriptions 9-28

Master engine

alert frequency B-5

alert frequency parameters (table) B-5

described B-3

event actions B-6

general parameters (table) B-4

promiscuous delta B-5

universal parameters B-4

memory for IDM 1-42, C-56

merging configuration files C-2

Meta engine

described 5-24, B-13

parameters (table) B-14

Signature Event Action Processor 5-24, B-13

Meta Event Generator described 6-32

MIBs supported 8-6, C-19

minor updates described 13-4

Miscellaneous tab

configuring

application policy 5-67

IP fragment reassembly mode 5-71

IP logging 5-80

TCP stream reassembly mode 5-78

described 5-57

field descriptions 5-58

user roles 5-57

modes

anomaly detection detect 7-3

anomaly detection inactive 7-3

anomaly detection learning accept 7-3

Bypass 3-26

Inline Interface Pair 3-13

inline VLAN pair 3-13

promiscuous 3-12

VLAN groups 3-13

modify packets inline modes 4-3

monitoring

events 6-35

KBs 7-40, 12-13

Viewer privileges A-26

moving OS maps 6-29

Multi String engine

described B-14

parameters (table) B-15

Regex B-14

N

Neighborhood Discovery

options B-11

types B-11

Network Blocks pane

configuring 9-34, 12-6

described 9-34, 12-5

field descriptions 9-34, 12-5

user roles 9-34, 12-5

Network pane

configuring 2-3

described 2-2

field definitions 2-2

TLS/SSL 2-3

user roles 2-2

Network Timing Protocol see NTP

never block

hosts 9-7

networks 9-7

NM-CIDS

bootloader

described 14-33

file 14-33

initializing 1-28

password recovery 2-7, C-10

reimaging 14-30, 14-31

setup command 1-28

system image file 14-30

time sources 2-24, C-15

upgrading the bootloader 14-33

Normalizer engine

described B-16

IP fragment reassembly B-16

parameters (table) B-18

TCP stream reassembly B-16

NotificationApp

alert information A-8

described A-3

functions A-8

SNMP gets A-8

SNMP traps A-8

statistics A-10

system health information A-9

NTP

authenticated 2-30

configuring servers 2-29

described 2-23, C-14

incorrect configuration C-16

sensor time source 2-29, 2-30

time synchronization 2-23, C-14

unauthenticated 2-30

O

obtaining

cryptographic account 13-2

IPS software 13-1

operation settings

configuring 7-11

user roles 7-10

Operation Settings tab

described 7-10

field descriptions 7-10

user roles 7-10

Operator privileges A-26

OS Identifications tab

described 6-26

field descriptions 6-27

OS maps

adding 6-29

configuring 6-29

deleting 6-29

editing 6-29

moving 6-29

Other Protocols tab

described 7-26, 7-34

describing 7-18, 7-26

enabling other protocols 7-18

external zone 7-34

field descriptions 7-18, 7-34

illegal zone 7-26

P

partitions

application A-3

maintenance A-3

recovery A-3

passive OS fingerprinting

configuring 6-27

described 6-25

components 6-26

password recovery

AIP-SSM 2-8, C-11

appliances 2-5, C-8

described 2-4, C-7

disabling 2-9, C-12

GRUB menu 2-5, C-8

IDSM-2 2-7, C-10

IPS-4240 2-6, C-9

IPS-4255 2-6, C-9

NM-CIDS 2-7, C-10

platforms 2-4, C-7

ROMMON 2-6, C-9

troubleshooting 2-10, C-13

verifying 2-10, C-13

patch releases described 13-4

peacetime learning and anomaly detection 7-3

physical connectivity issues C-30

physical interfaces configuration restrictions 3-9

platforms and concurrent CLI sessions 1-43

policies and platform limitations 5-2, 6-11, 7-8

Post-Block ACLs 9-20, 9-21

Pre-Block ACLs 9-20, 9-21

prerequisites for blocking 9-5

promiscuous delta

calculating risk rating 6-3

described 6-3

promiscuous mode

described 3-12

packet flow 3-12

protocols

ARP B-10

CIDEE A-32

DCE B-28

DDoS B-45

H.323 B-23

H225.0 B-23

IDAPI A-28

IDCONF A-31

IDIOM A-30

IPv6 B-11

LOKI B-45

MSSQL B-29

Neighborhood Discovery B-11

Q.931 B-23

RDEP2 A-29

RPC B-28

SDEE A-31

Q

Q.931 protocol

described B-23

SETUP messages B-23

quarantined IP address events described 10-2

R

rate limiting

ACLs 9-5

configuring 9-13, 12-9

described 9-4, 12-7

managing 9-13, 12-9

percentages 9-12, 12-7

routers 9-4, 12-7

service policies 9-5

supported signatures 9-4, 12-7

Rate Limits pane

described 9-12, 12-7

field descriptions 9-12, 12-8

RDEP2

described A-29

functions A-29

messages A-29

responsibilities A-29

rebooting the sensor 11-5

Reboot Sensor pane

button functions 11-5

configuring 11-5

described 11-5

user roles 11-5

recover command 14-13

recovering

AIP-SSM C-67

application partition image 14-13

recovery/upgrade CD 14-29

recovery partition

described A-3

upgrading 14-6

reimaging

AIP-SSM 14-51

appliances 14-13

described 14-1

IDS-4215 14-17

IDSM-2 14-36

IPS-4240 14-21

IPS-4255 14-21

IPS-4260 14-25

IPS 4270-20 14-27

NM-CIDS 14-31

sensors 13-8, 14-1

removing the last applied upgrade 14-12

Rename Knowledge Base dialog box

field descriptions 7-44, 12-17

user roles 7-44, 12-17

renaming KBs 7-44, 12-17

reset not occurring for a signature C-50

resetting AIP-SSM C-67

Restore Defaults pane

button functions 11-4

configuring 11-4

described 11-4

user roles 11-4

restoring

current configuration C-4

defaults 11-4

retrieving events through RDEP2 (illustration) A-29

risk rating

calculating 6-2

described 6-25

example 6-11

ROMMON

described 14-15

IDS-4215 14-17

IPS-4240 14-21

IPS-4255 14-21

IPS-4260 14-25

IPS-4270 14-25

IPS 4270-20 14-27

password recovery 2-6, C-9

remote sensors 14-15

serial console port 14-15

TFTP 14-15

round-trip time see RTT

Router Blocking Device Interfaces pane

configuring 9-23

described 9-20

field descriptions 9-22

RPC portmapper B-30

RTT

described 14-15

TFTP limitation 14-15

rules0 event action rules default policy 6-11

rules0 pane

default 6-13

described 6-13

tabs 6-13

S

Save Knowledge Base dialog box

described 7-42, 12-15

field descriptions 7-42, 12-15

user roles 7-42, 12-15

saving KBs 7-43, 12-16

scheduling automatic upgrades 14-9

SDEE

defined A-31

HTTP A-31

protocol A-31

server requests A-31

security and SSH 2-13

security information on Cisco Security Center 13-16

security policies described 5-1, 6-1, 7-1

sending commands through RDEP2 (illustration) A-30

sensing interfaces

described 3-3

modes 3-3

PCI cards 3-3

sensor

blocking itself 9-8

not seeing packets C-33

process not running C-29

SensorApp

Alarm Channel A-23

Analysis Engine A-23

described A-3

packet flow A-23

processors A-22

responsibilities A-22

Signature Event Action Handler A-22, A-24

Sensor Key pane

button functions 2-18

described 2-17

field descriptions 2-18

sensor SSH key

displaying 2-18

generating 2-18

user roles 2-17

sensors

access problems C-24

asymmetric traffic and disabling anomaly detection C-19

configuring to use NTP 2-30

corrupted SensorApp configuration C-35

diagnostics reports 11-9

disaster recovery C-6

downgrading 14-12

incorrect NTP configuration C-16

initializing 1-3, 2-1

interface support 3-4

IP address conflicts C-27

license 1-53, 13-12

loose connections C-22

misconfigured access lists C-26

no alerts C-32, C-59

not seeing packets C-33

NTP time source 2-30

NTP time synchronization 2-23, C-14

partitions A-3

physical connectivity C-30

preventive maintenance C-2

rebooting 11-5

recovering the system image 13-8

reimaging 13-8, 14-1

restoring defaults 11-4

sensing process not running C-29

setting up 2-1

setup command 1-3, 1-6, 2-1

shutting down 11-6

statistics 11-10

system images 13-8

system information 11-11

time sources 2-23, C-14

troubleshooting software upgrades C-55

updating 11-3, 11-7

using NTP time source 2-29

serial number and the show inventory command C-69

Server Certificate pane

button functions 2-22

certificate

displaying 2-22

generating 2-22

described 2-21

field descriptions 2-22

user roles 2-21

service account

creating C-5

described A-27, C-4

privileges A-26

TAC A-27

troubleshooting A-27

Service DNS engine

described B-19

parameters (table) B-19

Service engine

described B-18

Layer 5 traffic B-18

Service FTP engine

described B-20

parameters (table) B-21

PASV port spoof B-20

Service Generic Advanced engine described B-22

Service Generic engine

described B-21

parameters (table) B-22

Service H225 engine

ASN.1PER validation B-23

described B-23

features B-23

parameters (table) B-24

TPKT validation B-23

Service HTTP engine

custom signature 5-52

described 5-52, B-25

example signature 5-52

parameters (table) B-26

Service IDENT engine

described B-27

parameters (table) B-27

Service MSRPC engine

DCS/RPC protocol B-28

described B-28

parameters (table) B-28

Service MSSQL engine

described B-29

MSSQL protocol B-29

parameters (table) B-29

Service NTP engine

described B-29

parameters (table) B-29

service packs described 13-4

Service privileges A-26

service role 2-34, A-27

Service RPC engine

described B-29

parameters (table) B-29, B-30

RPC portmapper B-30

Service SMB Advanced engine

described B-32

parameters (table) B-33

Service SMB engine

described B-31

parameters (table) B-31

Service SNMP engine

described B-34

parameters (table) B-35

Service SSH engine

described B-35

parameters (table) B-35

Service TNS engine

described B-36

parameters (table) B-36

setting

current KBs 7-43, 12-16

system clock 2-32

setting up

sensors 2-1

terminal servers 14-16

setup command 1-3, 1-6, 1-14, 1-21, 1-28, 1-33, 2-1

show events command C-87, C-88

show interfaces command C-86

show inventory command C-69

show module 1 details command C-66

show settings command 2-10, C-13

show statistics command C-76

show statistics virtual-sensor command C-23, C-76

show tech-support command

described C-70

output C-71

show version command C-73

Shut Down Sensor pane

button functions 11-5

configuring 11-6

described 11-5

user roles 11-5

shutting down the sensor 11-6

sig0 pane

default 5-3

described 5-3

tabs 5-3

signature/virus update files described 13-5

Signature Configuration tab

described 5-4

field descriptions 5-5

signatures

adding 5-14

assigning actions 5-18

cloning 5-15

disabling 5-13

enabling 5-13

tuning 5-17

signature definition policies

adding 5-2

cloning 5-2

default policy 5-2

deleting 5-2

sig0 5-2

Signature Definitions pane

described 5-2

field descriptions 5-2

signature engines

AIC 5-60, B-8

Atomic B-9

Atomic ARP B-10

Atomic IP B-10

Atomic IPv6 B-11

creating custom signatures 5-28

described B-1

event actions B-6

Flood B-12

Flood Host B-12

Flood Net B-13

list B-2

Meta 5-24, B-13

Multi String B-14

Normalizer B-16

Service B-18

Service DNS B-19

Service FTP B-20

Service Generic B-21

Service Generic Advanced B-22

Service H225 B-23

Service HTTP 5-52, B-25

Service IDENT B-27

Service MSRPC B-28

Service MSSQL B-29

Service NTP engine B-29

Service RPC B-29

Service SMB B-31

Service SMB Advanced B-32

Service SNMP B-34

Service SSH engine B-35

Service TNS B-36

State B-37

String 5-50, B-38

supported by IDM 5-27, 5-43

Sweep B-41

Sweep Other TCP B-43

Traffic Anomaly 7-5, B-43

Traffic ICMP B-45

Trojan B-46

signature engine update files described 13-5

Signature Event Action Filter

described 6-6

parameters 6-6, A-24

Signature Event Action Handler

alarm channel 6-5, A-24

components 6-5, A-24

described 6-6, A-24

figure 6-6, A-25

Signature Event Action Override described 6-6, A-24

Signature Event Action Processor

described 6-5, A-22

flow of signature events 6-6, A-25

signature fidelity rating

calculating risk rating 6-2

described 6-2

signatures

adding 5-14

alert frequency 5-21

assigning actions 5-18

cloning 5-16

custom 5-4

default 5-4

described 5-3

disabling 5-13

editing 5-17

enabling 5-13

false positives 5-3

no TCP reset C-50

rate limits 9-4, 12-7

subsignatures 5-4

tuned 5-4

tuning 5-17

signature variables

adding 5-56

deleting 5-56

described 5-55

editing 5-56

Signature Variables tab

configuring 5-56

field descriptions 5-56

Signature Wizard unsupported signature engines 5-27, 5-43

SNMP

configuring 8-2

described 8-1

Get 8-1

GetNext 8-1

Set 8-1

supported MIBs 8-6, C-19

Trap 8-1

SNMP General Configuration pane

configuring 8-2

described 8-2

field descriptions 8-2

user roles 8-2

SNMP traps

configuring 8-4

described 8-1

SNMP Traps Configuration pane

configuring 8-4

field descriptions 8-4

software architecture

ARC (illustration) A-12

IDAPI (illustration) A-28

RDEP2 (illustration) A-29

software bypass

supported configurations 3-11

with hardware bypass 3-11

software downloads Cisco.com 13-1

software file names

recovery (illustration) 13-5

signature/virus updates (illustration) 13-4

signature engine updates (illustration) 13-5

system image (illustration) 13-5

software release examples

platform-dependent 13-7

platform identifiers 13-7

platform-independent 13-6

software updates

supported FTP servers 14-2

supported HTTP/HTTPS servers 14-2

SPAN port issues C-30

SSH

described 2-13

security 2-13

SSH Server

private keys A-20

public keys A-20

standards

CIDEE A-32

SDEE A-31

State engine

Cisco Login B-37

described B-37

LPR Format String B-37

parameters (table) B-37

SMTP B-37

statistics display 11-10

Statistics pane

button functions 11-10

categories 11-9

described 11-9

user roles 11-9

using 11-10

String engine described 5-50, B-38

String ICMP engine parameters (table) B-38

String TCP engine

custom signature 5-50

example signature 5-50

parameters (table) B-39

String UDP engine parameters (table) B-40

subinterface 0 described 3-14

subsignatures described 5-4

summarization

described 6-5

Fire All 6-5

Fire Once 6-5

Global Summarization 6-5

Meta engine 6-5

Summary 6-5

Summarizer described 6-32

Summary pane

described 3-15

field descriptions 3-15

supported

FTP servers 14-2

HTTP/HTTPS servers 14-2

IDSM-2 configurations C-61

IPS interfaces for CSA MC 10-4

Sweep engine

described B-40, B-41

parameters (table) B-41, B-43

Sweep Other TCP engine described B-43

switch commands for troubleshooting C-61

system architecture

directory structure A-32

supported platforms A-1

system clock setting 2-32

system components (IDAPI) A-28

System Configuration Dialog

described 1-3

example 1-4

system design (illustration) A-1

system images

installing IPS-4240 14-21

installing IPS-4255 14-21

sensors 13-8

system information display 11-11

System Information pane

button functions 11-11

described 11-10

user roles 11-11

using 11-11

system resources status and the Home window 1-2

T

TAC

service account A-27, C-4

show tech-support command C-70

target value rating

adding 6-18

calculating risk rating 6-3

configuring 6-18

deleting 6-18

described 6-3, 6-17

editing 6-18

Target Value Rating tab

configuring 6-18

field descriptions 6-18

TCP fragmentation described B-16

TCP Protocol tab

described 7-15, 7-24, 7-31

enabling TCP 7-15

external zone 7-31

field descriptions 7-15, 7-24, 7-31

illegal zone 7-24

TCP reset interfaces

conditions 3-8

described 3-7

list 3-7

TCP resets not occurring C-50

TCP stream reassembly

described 5-73

mode 5-78

parameters (table) 5-73

signatures (table) 5-73

terminal servers setup 14-16

testing fail-over 3-11

TFN2K

described B-45

Trojans B-46

TFTP and RTT 14-15

TFTP servers

recommended

UNIX 14-15

Windows 14-15

threat rating described 6-4

Thresholds for KB Name window

described 7-40, 12-13

field descriptions 7-40, 12-13

filtering information 7-40, 12-13

user roles 7-40, 12-13

time correction on the sensor 2-28, C-17

Time pane

configuring 2-27

described 2-23

field descriptions 2-25, 2-26

user roles 2-23

time sources

AIM-IPS 2-24, C-15

AIP-SSM 2-24, C-15

appliances 2-23, C-14

IDSM-2 2-23, C-14

NM-CIDS 2-24, C-15

time synchronization and IPS modules 2-25, C-16

TLS

certificates 1-47, 2-18

handshaking 1-47, 2-19

understanding 1-47, 2-3, 2-18

Traffic Anomaly engine

described 7-5, B-43

protocols 7-5, B-43

signatures 7-5, B-43

traffic flow notifications

configuring 3-28

overview 3-27

Traffic Flow Notifications pane

configuring 3-28

field descriptions 3-27

Traffic ICMP engine

DDoS B-45

described B-45

LOKI B-45

parameters (table) B-45

TFN2K B-45

Transport Layer Security see TLS

trial license key 1-50, 13-9

Tribe Flood Network 2000 see TFN2K

Tribe Flood Network see TFN

Trojan engine

BO2K B-46

described B-46

TFN2K B-46

Trojans

BO B-46

BO2K B-46

LOKI B-45

TFN2K B-46

troubleshooting

AIP-SSM

commands C-66

debugging C-67

recovering C-67

reset C-67

Analysis Engine busy C-58

applying software updates C-53

ARC

blocking not occurring for signature C-42

device access issues C-39

enabling SSH C-42

inactive state C-38

misconfigured master blocking sensor C-43

verifying device interfaces C-41

automatic updates C-54

cannot access sensor C-24

cidDump C-91

cidLog messages to syslog C-49

communication C-24

corrupted SensorApp configuration C-35

debug logger zone names (table) C-49

debug logging C-44

disaster recovery C-6

duplicate sensor IP addresses C-27

enabling debug logging C-45

external product interfaces 10-11, C-22

faulty DIMMs C-36

gathering information C-69

IDM

cannot access sensor C-58

will not load C-57

IDSM-2

command and control port C-64

diagnosing problems C-60

not online C-64

serial cable C-66

status indicator C-62

switch commands C-61

TCP reset port C-66

IPS modules and time drift 2-25, C-16

manual block to bogus host C-42

misconfigured access list C-26

no alerts C-32, C-59

NTP C-50

password recovery 2-10, C-13

physical connectivity issues C-30

preventive maintenance C-2

reset not occurring for a signature C-50

sensing process not running C-29

sensor events C-87

sensor loose connections C-22

sensor not seeing packets C-33

sensor software upgrade C-55

service account C-4

show events command C-87

show interfaces command C-85, C-86

show statistics command C-76

show tech-support command C-70, C-71

show version command C-73

software upgrade

IDS-4235 C-52

IDS-4250 C-52

software upgrades C-52

SPAN port issue C-30

upgrading from 5.x to 6.0 C-52

verifying Analysis Engine is running C-20

verifying ARC status C-37

Trusted Hosts pane

configuring 2-20

described 2-20

field definitions 2-20

tuned signatures described 5-4

tuning

AIC signatures 5-68

IP fragment reassembly signatures 5-72

signatures 5-17

U

UDP Protocol tab

described 7-16, 7-25, 7-32

enabling UDP 7-16

external zone 7-32

field descriptions 7-17, 7-33

illegal zone 7-25

unassigned VLAN groups described 3-14

unauthenticated NTP 2-30

understanding

SSH 2-13

time on the sensor 2-23, C-14

UNIX-style directory listings 11-2

Update Sensor pane

configuring 11-7

described 11-6

field descriptions 11-6

user roles 11-6

updating

Cisco.com 11-6

FTP server 11-6

sensors 11-7

upgrade

command 14-3

files 14-3

upgrade command 14-6

upgrading

5.x to 6.0 13-8

files 14-3

from 5.x to 6.0 C-52

maintenance partition

IDSM-2 (Catalyst software) 14-46

IDSM-2 (Cisco IOS software) 14-47

minimum required version 13-8

recovery partition 14-6, 14-13

uploading KBs

FTP 7-45, 12-18

SCP 7-45, 12-18

Upload Knowledge Base to Sensor dialog box

described 7-45, 12-18

field descriptions 7-45, 12-18

user roles 7-45, 12-18

URL for Cisco Security Center 13-16

user roles

Administrator A-26

Operator A-26

Service A-26

Viewer A-26

Users pane

configuring 2-35

described 2-33

field definitions 2-35

user roles 2-34

using

debug logging C-44

TCP reset interface 3-8

V

VACLs

described 9-2

Post-Block 9-25

Pre-Block 9-25

verifying

installation

AIM-IPS C-69

NME-IPS C-69

password recovery 2-10, C-13

sensor initialization 1-39

sensor setup 1-39

Viewer privileges A-26

viewing

IP logs 12-21

statistics 11-10

system information 11-11

virtual sensors

adding 4-5

default virtual sensor 4-2, 4-4

deleting 4-5

described 4-1, 4-4

editing 4-5

stream segregation 4-3

Virtual Sensors pane

described 4-4

field descriptions 4-4

VLAN groups

802.1q encapsulation 3-14

configuration restrictions 3-10

configuring 3-24

deploying 3-23

described 3-13

switches 3-23

VLAN Groups pane

configuring 3-24

described 3-23

field descriptions 3-24

VLAN IDs 3-23

VLAN pairs configuration 3-22

VLAN Pairs pane

configuring 3-22

field descriptions 3-21

overview 3-21

W

watch list rating

calculating risk rating 6-3

described 6-3

Web Server

described A-3, A-21

HTTP 1.0 and 1.1 support A-21

private keys A-20

public keys A-20

RDEP2 support A-21

worms

attacks and histograms 7-12

Blaster 7-2

Code Red 7-2

described 7-2

Nimbda 7-2

protocols 7-2

Sasser 7-2

scanners 7-2

Slammer 7-2

SQL Slammer 7-2

Z

zones

external 7-4

illegal 7-4

internal 7-4