Table Of Contents
Numerics - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - Z
Index
Numerics
4GE bypass interface card
configuration restrictions 3-11
described 3-11
802.1q encapsulation
VLAN groups 3-14
A
accessing IPS software 13-2
access list misconfiguration C-26
ACLs
described 9-2
Post-Block 9-20, 9-21
Pre-Block 9-20, 9-21
Active Host Blocks pane
configuring 9-32, 12-4
described 9-31, 12-2
field descriptions 9-31, 12-3
user roles 9-31, 12-2
active update bulletin subscription 13-15
ad0 pane
default 7-10
described 7-10
tabs 7-10
Add Active Host Block dialog box field descriptions 9-32, 12-3
Add Allowed Host dialog box
field descriptions 2-12
user roles 2-11
Add Authorized Key dialog box
field descriptions 2-14
user roles 2-14
Add Blocking Device dialog box
field descriptions 9-17
user roles 9-17
Add Cat 6K Blocking Device Interface dialog box
field descriptions 9-26
user roles 9-25
Add Configured OS Map dialog box
field descriptions 6-28
user roles 6-25
Add Destination Port dialog box field descriptions 7-16, 7-17, 7-24, 7-25, 7-32, 7-33
Add Device Login Profile dialog box
field descriptions 9-15
user roles 9-14
Add Event Action Filter dialog box
field descriptions 6-20
user roles 6-19
Add Event Action Override dialog box
field descriptions 6-14
user roles 6-13
Add Event Variable dialog box
field descriptions 6-31
user roles 6-30
Add External Product Interface dialog box
field descriptions 10-5
user roles 10-1
Add Histogram dialog box field descriptions 7-16, 7-17, 7-19, 7-25, 7-26, 7-27, 7-32, 7-33, 7-34
adding
active host blocks 9-32, 12-4
a host never to be blocked 9-11
anomaly detection policies 7-9
event action filters 6-23
event action overrides 6-16
event action rules policies 6-12
event variables 6-31
external product interfaces 10-8
network blocks 9-34, 12-6
OS maps 6-29
signature definition policies 5-2
signatures 5-14
signature variables 5-56
target value ratings 6-18
virtual sensors 4-5
Add Inline VLAN Pair dialog box
field descriptions 3-21
user roles 3-20
Add Interface Pair dialog box
field descriptions 3-19
user roles 3-19
Add IP Logging dialog box
field descriptions 12-21
user roles 12-20
Add Known Host Key dialog box
field descriptions 2-16
user roles 2-16
Add Master Blocking Sensor dialog box
field descriptions 9-29
user roles 9-28
Add Network Block dialog box
field descriptions 9-34
user roles 9-34
Add Never Block Address dialog box
field descriptions 9-10
user roles 9-7
Add Policy dialog box
field descriptions 5-2, 6-12, 7-8
user roles 5-2, 6-11, 7-8
Add Posture ACL dialog box
field descriptions 10-7
user roles 10-1
Add Protocol Number dialog box field descriptions 7-18, 7-26, 7-34
Add Rate Limit dialog box
field descriptions 9-13
user roles 9-12
Address Resolution Protocol see ARP
Add Router Blocking Device Interface dialog box
field descriptions 9-23
user roles 9-20
Add Signature dialog box
field descriptions 5-7
user roles 5-4
Add Signature Variable dialog box
field descriptions 5-56
user roles 5-55
Add SNMP Trap Destination dialog box
field descriptions 8-4
user roles 8-3
Add Target Value Rating dialog box
field descriptions 6-18
user roles 6-17
Add Trusted Host dialog box
field descriptions 2-20
user roles 2-20
Add User dialog box
field descriptions 2-35
user roles 2-33
Add Virtual Sensor dialog box
described 4-5
field descriptions 4-5
Add VLAN Group dialog box
field descriptions 3-24
user roles 3-23
Administrator privileges A-26
Advanced Alert Behavior Wizard
Alert Dynamic Response Fire All window field descriptions 5-42
Alert Dynamic Response Fire Once window field descriptions 5-42
Alert Dynamic Response Summary window field descriptions 5-41
Alert Summarization window field descriptions 5-41
Event Count and Interval window field descriptions 5-40
Global Summarization window field descriptions 5-42
advisory for cryptographic products 1-1
AIC engine
AIC FTP B-7
AIC HTTP B-7
described 5-60, B-7
features B-7
signatures (example) 5-68
AIC FTP engine parameters (table) B-9
AIC HTTP engine parameters (table) B-8
AIC policy configuration 5-67
AIC policy enforcement
default configuration 5-61, B-7
described 5-61, B-7
sensor oversubscription 5-61, B-7
AIM-IPS
initializing 1-33
setup command 1-33
system image installation 14-48
time sources 2-24, C-15
verifying installation C-69
AIP-SSM
Bypass mode 3-27
initializing 1-21
password recovery 2-8, C-11
recovering C-67
reimaging 14-51
resetting C-67
setup command 1-21
system image installation 14-51
time sources 2-24, C-15
Alarm Channel described 6-5, A-24
alert frequency
aggregation 5-21
configuring 5-21
controlling 5-21
modes B-5
alert profile in Home window 1-2
alert summary in Home window 1-2
Allowed Hosts pane
configuring 2-12
described 2-11
alternate TCP reset interface configuration restrictions 3-9
Analysis Engine
busy C-23
described 4-1
global variables 4-7
verify it is running C-20
virtual sensors 4-1
Analysis Engine busy
error messages C-23
IDM exits C-58
anomaly detection
asymmetric environment 7-2
caution 7-2
configuration sequence 7-4
default configuration (example) 7-4
described 7-2
detect mode 7-3
disabling C-19
event actions 7-6, B-43
inactive mode 7-3
learning accept mode 7-3
learning process 7-3
limiting false positives 7-12
protocols 7-2
signatures (table) 7-6, B-44
worm attacks 7-12
worms 7-2
zones 7-4
Anomaly Detection pane
described 7-8
field descriptions 7-8, 7-39, 12-12
user roles 7-8, 7-39, 12-12
anomaly detection policies
ad0 7-8
adding 7-9
cloning 7-9
default policy 7-8
deleting 7-9
user roles 7-8
appliances
application partition image 14-13
GRUB menu 2-5, C-8
initializing 1-6
password recovery 2-5, C-8
recovering the software image 14-29
terminal servers
described 14-16
setting up 14-16
time sources 2-23, C-14
upgrading the recovery partition 14-6
Application Inspection and Control see AIC
application partition
described A-3
image recovery 14-13
application policy enforcement described 5-61, B-7
applications in XML format A-2
applying software updates C-53
ARC
ACLs 9-21, A-12
authentication A-13
blocking
application 9-1
connection-based A-16
not occurring for signature C-42
unconditional blocking A-16
block response A-12
Catalyst 6000 series switch
VACL commands A-18
VACLs A-18
Catalyst switches
VACLs A-15
VLANs A-15
checking status 9-3, 9-4, 12-7
described A-2
design 9-2
device access issues C-39
enabling SSH C-42
features A-12
firewalls
AAA A-17
connection blocking A-17
NAT A-17
network blocking A-17
postblock ACL A-15
preblock ACL A-15
shun command A-17
TACACS+ A-17
formerly Network Access Controller 9-3
functions 9-1, A-11
illustration A-11
inactive state C-38
interfaces A-13
maintaining states A-15
managed devices 9-7
master blocking sensors A-13
maximum blocks 9-2
misconfigured master blocking sensor C-43
nac.shun.txt file A-15
NAT addressing A-14
number of blocks A-14
postblock ACL A-15
preblock ACL A-15
prerequisites 9-5
rate limiting 9-4, 12-7
responsibilities A-11
single point of control A-14
SSH A-12
supported devices 9-6, A-14
Telnet A-12
troubleshooting C-36
VACLs A-12
verifying device interfaces C-41
verifying status C-37
ARP
Layer 2 signatures B-10
protocol B-10
ARP spoof tools
dsniff B-10
ettercap B-10
Assign Actions dialog box field descriptions 5-11
assigning actions to signatures 5-18
asymmetric environment and anomaly detection 7-2
asymmetric traffic and disabling anomaly detection C-19
Atomic ARP engine
described B-10
parameters (table) B-10
Atomic IP engine
described B-10
parameters (table) B-10
Atomic IPv6 engine
described B-11
Neighborhood Discovery protocol B-11
signatures B-11
signatures (table) B-12
attack relevance rating
calculating risk rating 6-3
described 6-3, 6-25
Attack Response Controller
described A-2
formerly known as Network Access Controller A-2
See ARC
attack severity rating
calculating risk rating 6-3
described 6-3
authenticated NTP 2-30
AuthenticationApp
authenticating users A-20
described A-3
login attempt limit A-19
method A-19
responsibilities A-19
secure communications A-20
sensor configuration A-19
Authorized Keys pane
configuring 2-14
described 2-14
field descriptions 2-14
RSA authentication 2-14
RSA key generation tool 2-15
automatic updates
Cisco.com 11-1
servers
FTP 11-1
SCP 11-1
troubleshooting C-54
automatic upgrade
examples 14-11
required information 14-7
autonegotiation and hardware bypass 3-12
Auto Update pane
configuring 11-3
described 11-1
field descriptions 11-2
UNIX-style directory listings 11-2
user roles 11-1
auto-upgrade-option command 14-7
B
backing up
configuration C-2
current configuration C-4
BackOrifice 2000 see BO2K
BackOrifice see BO
blocking
described 9-1
disabling 9-8
master blocking sensor 9-28
necessary information 9-3
not occurring for signature C-42
prerequisites 9-5
supported devices 9-6
types 9-2
Blocking Devices pane
configuring 9-18
described 9-17
field descriptions 9-17
ssh host-key command 9-18
Blocking Properties pane
adding a host never to be blocked 9-11
configuring 9-10
described 9-7
field descriptions 9-8
BO
described B-46
Trojans B-46
BO2K
described B-46
Trojans B-46
bootloader
explaining 14-33
upgrading 14-33
Bypass mode
AIP-SSM 3-27
described 3-26
Bypass pane
field descriptions 3-26
user roles 3-26
C
calculating risk rating
attack relevance rating 6-3
attack severity rating 6-3
promiscuous delta 6-3
signature fidelity rating 6-2
target value rating 6-3
watch list rating 6-3
cannot access sensor C-24
Cat 6K Blocking Device Interfaces pane
configuring 9-26
described 9-25
field descriptions 9-26
certificates
displaying 2-22
generating 2-22
Internet Explorer 1-48
changing Microsoft IIS to UNIX-style directory listings 11-2
changing the memory
Java Plug-in on Linux 1-43, C-57
Java Plug-in on Solaris 1-43, C-57
Java Plug-in on Windows 1-42, C-56
cidDump and obtaining information C-91
CIDEE
defined A-32
example A-32
IPS extensions A-32
protocol A-32
supported IPS events A-32
Cisco.com
accessing software 13-2
Active Update Bulletins 13-15
downloading software 13-1
IPS software 13-1
software downloads 13-1
Cisco IOS and rate limiting 9-4, 12-7
cisco-security-agents-mc-settings command 10-7
Cisco Security Center
described 13-16
URL 13-16
Cisco Services for IPS
service contract 1-51, 13-10
supported products 1-51, 13-10
clear events command 2-28, 2-33, C-17, C-91
clearing
events 2-33, C-91
statistics C-77
clear password command 2-7, 2-8, C-10, C-11
CLI described A-3, A-26
clock set command 2-32
Clone Policy dialog box
field descriptions 5-2, 6-12, 7-8
user roles 5-2, 6-11, 7-8
Clone Signature dialog box
field descriptions 5-7
user roles 5-4
cloning
anomaly detection policies 7-9
event action rules policies 6-12
signature definition policies 5-2
signatures 5-16
command and control interfaces
described 3-2
list 3-2
commands
auto-upgrade-option 14-7
cisco-security-agents-mc-settings 10-7
clear events 2-28, 2-33, C-17, C-91
clear password 2-7, 2-8, C-10, C-11
clock set 2-32
copy backup-config C-3
copy current-config C-3
copy license-key 13-13
debug module-boot C-67
downgrade 14-12
hw-module module 1 reset C-67
hw-module module slot_number password-reset 2-8, C-11
setup 1-3, 1-6, 1-14, 1-21, 1-28, 1-33, 2-1
show events C-88
show inventory C-69
show module 1 details C-66
show settings 2-10, C-13
show statistics C-76
show statistics virtual-sensor C-23, C-76
show tech-support C-70
show version C-73
upgrade 14-3, 14-6
Compare Knowledge Bases dialog box field descriptions 7-41, 12-14
comparing KBs 7-42, 12-15
configuration files
backing up C-2
merging C-2
configuration restrictions
alternate TCP reset interface 3-9
inline interface pairs 3-9
inline VLAN pairs 3-9
interfaces 3-9
physical interfaces 3-9
VLAN groups 3-10
Configure Summertime dialog box field descriptions 2-26
configuring
active host blocks 9-32, 12-4
AIC policy parameters 5-67
allowed hosts 2-12
application policy 5-68
authorized keys 2-14
automatic upgrades 14-9
blocking devices 9-18
blocking properties 9-10
Cat 6K blocking device interfaces 9-26
CSA MC support for IPS interfaces 10-4
device login profiles 9-15
event action filters 6-23
events 6-35
event variables 6-31
external zone 7-35
general settings 6-33
illegal zone 7-27
interface pairs 3-19
interfaces 3-17
interfaces (sequence) 3-8
internal zone 7-19
IP fragment reassembly signatures 5-72
IP logging 12-21
known host keys 2-16
learning accept mode 7-13
maintenance partition
IDSM-2 (Catalyst software) 14-39
IDSM-2 (Cisco IOS software) 14-43
master blocking sensor 9-29
network blocks 9-34, 12-6
NTP servers 2-29
operation settings 7-11
OS maps 6-29
rate limiting 9-13, 12-9
rate limiting devices 9-18
router blocking device interfaces 9-23
sensor to use NTP 2-30
SNMP 8-2
SNMP traps 8-4
target value ratings 6-18
TCP fragment reassembly parameters 5-78
time 2-27
traffic flow notifications 3-28
trusted hosts 2-20
upgrades 14-4
users 2-35
VLAN groups 3-24
VLAN pairs 3-22
control transactions
characteristics A-7
request types A-7
cookies and IDM 1-47
copy backup-config command C-3
copy current-config command C-3
copy license-key command 13-13
correcting time on the sensor 2-28, C-17
creating
custom signatures
not using signature engines 5-29
Service HTTP 5-52
String TCP 5-50
using signature engines 5-28
Meta signatures 5-24
Post-Block VACLs 9-25
Pre-Block VACLs 9-25
service account C-5
cryptographic account
Encryption Software Export Distribution Authorization from 13-2
obtaining 13-2
cryptographic products and IDM 1-1
CSA MC
configuring IPS interfaces 10-4
host posture events 10-2, 10-4
quarantined IP address events 10-2
supporting IPS interfaces 10-4
CtlTransSource
described A-2, A-10
illustration A-10
current configuration backup C-2
current KB settings 7-43, 12-16
custom signatures
described 5-4
Meta signature 5-24
Custom Signature Wizard
Alert Response window field descriptions 5-39
Atomic IP Engine Parameters window field descriptions 5-32
described 5-27
ICMP Traffic Type window field descriptions 5-38
Inspect Data window field descriptions 5-39
MSRPC Engine Parameters window field descriptions 5-34
no signature engine sequence 5-29
Protocol Type window field descriptions 5-31
Service HTTP Engine Parameters window field descriptions 5-33
Service RPC Engine Parameters window field descriptions 5-34
Service Type window field descriptions 5-39
signature engine sequence 5-28
Signature Identification window field descriptions 5-31
State Engine Parameters window field descriptions 5-35
String ICMP Engine Parameters window field descriptions 5-35
String TCP Engine Parameters window field descriptions 5-36
String UDP Engine Parameters window field descriptions 5-37
Sweep Engine Parameters window field descriptions 5-37
TCP Sweep Type window field descriptions 5-39
TCP Traffic Type window field descriptions 5-38
UDP Sweep Type window field descriptions 5-38
UDP Traffic Type window field descriptions 5-38
user roles 5-27
Welcome window field descriptions 5-31
D
data structure examples A-7
DDoS
protocols B-45
Stacheldraht B-45
TFN B-45
debug logging enabling C-45
debug-module-boot command C-67
default KB filename 7-13
default policies
ad0 7-8
rules0 6-11
sig0 5-2
defaults restoring 11-4
default virtual sensor vs0 4-2
deleting
anomaly detection policies 7-9
event action filters 6-23
event action overrides 6-16
event action rules policies 6-12
event variables 6-31
imported OS values 6-38, 12-11
KBs 7-43, 12-16
learned OS values 6-37, 12-10
OS maps 6-29
signature definition policies 5-2
signature variables 5-56
target value ratings 6-18
virtual sensors 4-5
Denial of Service see DoS
denied attackers
clearing list 12-2
hit count 12-1
resetting hit counts 12-2
Denied Attackers pane
described 12-1
field descriptions 12-1
user roles 12-1
using 12-2
detect mode and anomaly detection 7-3
device access issues C-39
device information in the Home window 1-2
Device Login Profiles pane
configuring 9-15
described 9-14
field descriptions 9-15
Diagnostics Report pane
button functions 11-9
described 11-8
user roles 11-8
using 11-9
diagnostics reports 11-9
disabling
anomaly detection C-19
blocking 9-8
interfaces 3-17
password recovery 2-9, C-12
disaster recovery C-6
displaying
events C-89
password recovery setting 2-10, C-13
statistics C-77
tech support information C-71
version C-73
Distributed Denial of Service see DDoS
DoS tools (stick) B-5
downgrade command 14-12
downgrading sensors 14-12
downloading
KBs 7-45, 12-18
software 13-1
Download Knowledge Base From Sensor dialog box
described 7-44, 12-17
user roles 7-44, 12-17
duplicate IP addresses C-27
E
Edit Allowed Host dialog box
field definitions 2-12
user roles 2-11
Edit Authorized Key dialog box
field definitions 2-14
user roles 2-14
Edit Blocking Device dialog box
field descriptions 9-17
user roles 9-17
Edit Cat 6K Blocking Device Interface dialog box
field descriptions 9-26
user roles 9-25
Edit Configured OS Map dialog box
field descriptions 6-28
user roles 6-25
Edit Destination Port dialog box field descriptions 7-16, 7-17, 7-24, 7-32, 7-33
Edit Device Login Profile dialog box
field descriptions 9-15
user roles 9-14
Edit Event Action Filter dialog box
field descriptions 6-20
user roles 6-19
Edit Event Action Override dialog box
field descriptions 6-14
user roles 6-13
Edit Event Variable dialog box
field descriptions 6-31
user roles 6-30
Edit External Product Interface dialog box
field descriptions 10-5
user roles 10-1
Edit Histogram dialog box field descriptions 7-16, 7-17, 7-19, 7-25, 7-27, 7-32, 7-33, 7-34
editing
event action filters 6-23
event action overrides 6-16
event variables 6-31
interfaces 3-18
OS maps 6-29
signatures 5-17
signature variables 5-56
target value ratings 6-18
virtual sensors 4-5
Edit Inline VLAN Pair dialog box
field descriptions 3-21
user roles 3-20
Edit Interface dialog box
field descriptions 3-16
user roles 3-15
Edit Interface Pair dialog box
field descriptions 3-19
user roles 3-19
Edit IP Logging dialog box
field descriptions 12-21
user roles 12-20
Edit Known Host Key dialog box
field descriptions 2-16
user roles 2-16
Edit Master Blocking Sensor dialog box
field descriptions 9-29
user roles 9-28
Edit Never Block Address dialog box
field descriptions 9-10
user roles 9-7
Edit Posture ACL dialog box field descriptions 10-7
Edit Protocol Number dialog box field descriptions 7-26
Edit Router Blocking Device Interface dialog box
field descriptions 9-23
user roles 9-20
Edit Signature dialog box
field descriptions 5-7
user roles 5-4
Edit Signature Variable dialog box
field descriptions 5-56
user roles 5-55
Edit SNMP Trap Destination dialog box
field descriptions 8-4
user roles 8-3
Edit Target Value Rating dialog box
field descriptions 6-18
user roles 6-17
Edit User dialog box
field descriptions 2-35
user roles 2-33
Edit Virtual Sensor dialog box
field descriptions 4-5
user roles 4-4
Edit VLAN Group dialog box
field descriptions 3-24
user roles 3-23
enabling
debug logging C-45
event action filters 6-23
event action overrides 6-16
interfaces 3-17
Encryption Software Export Distribution Authorization form
cryptographic account 13-2
described 13-2
error message Analysis Engine is busy C-23
evAlert A-8
event action filters
adding 6-23
configuring 6-23
deleting 6-23
described 6-4
editing 6-23
enabling 6-23
Event Action Filters tab
configuring 6-23
described 6-19
field descriptions 6-19
event action overrides
adding 6-16
deleting 6-16
described 6-4
editing 6-16
enabling 6-16
Event Action Overrides tab
field descriptions 6-14
user roles 6-13
event action rules
default policy 6-11
example 6-10
functions 6-2
rules0 6-11
understanding 6-2
Event Action Rules pane
described 6-11
field descriptions 6-12
user roles 6-11
event action rules policies
adding 6-12
cloning 6-12
deleting 6-12
event actions
described 6-8
table 6-8
events
display configuration 6-35
displaying C-89
host posture 10-2
quarantined IP address 10-2
Events pane
configuring 6-35
described 6-34
field descriptions 6-34
Event Store
clearing events 2-28, C-17
data structures A-7
described A-2
examples A-6
responsibilities A-6
timestamp A-6
event types C-87
event variables
adding 6-31
configuring 6-31
deleting 6-31
editing 6-31
example 6-30
Event Variables tab
configuring 6-31
described 6-30
field descriptions 6-31
Event Viewer window field descriptions 6-35
evError A-8
evLogTransaction A-8
evShunRqst A-8
evStatus A-8
external product interfaces
adding 10-8
described 10-1
issues 10-3, C-21
troubleshooting 10-11, C-22
External Product Interfaces pane
field descriptions 10-4
user roles 10-1
external zone
configuring 7-35
protocols 7-31
user roles 7-31
External Zone tab
described 7-31
tabs 7-31
user roles 7-31
F
fail-over testing 3-11
false positives described 5-3
files
IDSM-2 password recovery 2-7, C-10
upgrade 14-3
finding the serial number C-69
Flood engine described B-12
Flood Host engine parameters (table) B-12
Flood Net engine parameters (table) B-13
FTP servers supported 14-2
G
general settings
configuring 6-33
described 6-32
General Settings tab
configuring 6-33
described 6-32
field descriptions 6-33
user roles 6-32
General tab
described 7-15, 7-23
enabling zones 7-15, 7-23
field descriptions 7-15, 7-23
generating diagnostics reports 11-9
Global Variables pane
described 4-7
field definitions 4-7
user roles 4-7
GRUB menu for password recovery 2-5, C-8
H
H.225.0 protocol B-23
H.323 protocol B-23
hardware bypass
autonegotiation 3-12
configuration restrictions 3-11
fail-over 3-11
IPS-4260 3-11
IPS 4270-20 3-11
supported configurations 3-11
with software bypass 3-11
Home window
auto refresh 1-2
described 1-2
host posture events
CSA MC 10-4
described 10-2
HTTP/HTTPS supported servers 14-2
HTTP deobfuscation
ASCII normalization 5-52, B-25
described 5-52, B-25
hw-module module 1 reset command C-67
hw-module module slot_number password-reset command 2-8, C-11
I
IDAPI
communications A-3, A-28
described A-3
functions A-28
illustration A-28
responsibilities A-28
IDCONF
described A-31
example A-31
RDEP2 A-31
XML A-31
IDIOM
defined A-30
messages A-30
IDM
advisory 1-1
Analysis Engine is busy C-58
certificates 1-47, 2-18
cookies 1-47
cryptographic products 1-1
described 1-1, 1-44, 1-45
GUI 1-1
Java Plug-in 1-42, C-56
logging in 1-44, 1-45
memory 1-42, C-56
prerequisites 1-44
Signature Wizard unsupported signature engines5-27, 5-43
TLS and SSL 1-47, 2-19
user interface 1-1
validating certificates 1-48
web browsers 1-1, 1-44, 1-45
will not load C-57
IDS-4215
BIOS upgrade 14-20
installing system image 14-17
installing the system image 14-17
ROMMON upgrade 14-20
upgrading
BIOS 14-20
ROMMON 14-20
IDSM-2
command and control port C-64
configuring
maintenance partition (Catalyst software) 14-39
maintenance partition (Cisco IOS software) 14-43
initializing 1-14
installing
system image (Catalyst software) 14-36
system image (Cisco IOS software) 14-37
password recovery 2-7, C-10
password recovery image file 2-7, C-10
reimaging 14-36
setup command 1-14
supported configurations C-61
time sources 2-23, C-14
upgrading
maintenance partition (Catalyst software) 14-46
maintenance partition (Cisco IOS software) 14-47
illegal zone
configuring 7-27
user roles 7-23
Illegal Zone tab
described 7-23
user roles 7-23
Imported OS pane
clearing 6-38, 12-11
described 6-37, 12-11
field descriptions 6-38, 12-11
imported OS values
clearing 6-38, 12-11
deleting 6-38, 12-11
user roles 6-37, 12-11
inactive mode and anomaly detection 7-3
initializing
AIM-IPS 1-33
AIP-SSM 1-21
appliances 1-6
IDSM-2 1-14
NM-CIDS 1-28
sensors 1-3, 2-1
verification 1-39
Inline Interface Pair mode
configuration restrictions 3-9
described 3-13
inline VLAN pair mode
configuration restrictions 3-9
described 3-13
supported sensors 3-13
installer major version described 13-6
installer minor version described 13-6
installing
AIM-IPS system image 14-48
license key 13-14
sensor license 1-53, 13-12
system image
AIP-SSM 14-51
IDS-4215 14-17
IDSM-2 (Catalyst software) 14-36
IDSM-2 (Cisco IOS software) 14-37
IPS-4240 14-21
IPS-4255 14-21
IPS-4260 14-25
IPS 4270-20 14-27
InterfaceApp described A-2
interface configuration sequence 3-8
interface pairs
configuring 3-19
described 3-19
Interface Pairs pane
configuring 3-19
described 3-19
field descriptions 3-19
interfaces
alternate TCP reset 3-2
command and control 3-2
configuration restrictions 3-9
configuring 3-17
described 3-1
disabling 3-17
editing 3-18
enabling 3-17
port numbers 3-1
sensing 3-2, 3-3
slot numbers 3-1
support (table) 3-4
TCP reset 3-7
VLAN groups 3-2
Interfaces pane
configuring 3-17
described 3-15
field descriptions 3-16
interface status and the Home window 1-2
internal zone
configuring 7-19
user roles 7-15
Internal Zone tab
described 7-15
user roles 7-15
Internet Explorer certificate validation 1-48
IP fragmentation described B-16
IP fragment reassembly
configuring 5-71
described 5-69
mode 5-71
parameters (table) 5-69
signatures 5-72
signatures (example) 5-72
signatures (table) 5-69
IP logging
described 5-79, 12-19
event actions 12-20
system performance 12-20
IP Logging pane
configuring 12-21
described 12-20
field descriptions 12-20
user roles 12-20
IP logs
circular buffer 12-20
states 12-19
TCP Dump 12-20
viewing 12-21
Wireshark 12-20
IPS
external communications A-29
internal communications A-28
IPS-4240
installing the system image 14-21
password recovery 2-6, C-9
reimaging 14-21
IPS-4255
installing the system image 14-21
password recovery 2-6, C-9
reimaging 14-21
IPS-4260
hardware bypass 3-11
installing the system image 14-25
reimaging 14-25
IPS 4270-20
hardware bypass 3-11
installing the system image 14-27
reimaging 14-27
IPS applications
summary A-33
table A-33
XML format A-2
IPS data
types A-7
XML document A-7
IPS events
evAlert A-8
evError A-8
evLogTransaction A-8
evShunRqst A-8
evStatus A-8
listed A-8
types A-8
IPS features
anomaly detection A-3
CSA collaboration A-3
enhanced password recovery A-3
passive OS fingerprinting A-3
signature policy virtualization A-3
threat rating A-3
IPS modules and time synchronization 2-25, C-16
IPS software
application list A-2
available files 13-1
configuring device parameters A-4
directory structure A-32
Linux OS A-1
new features A-3
obtaining 13-1
platform-dependent release examples 13-7
retrieving data A-4
security features A-4
tuning signatures A-4
updating A-4
user interaction A-4
versioning scheme 13-3
IPS software file names
major updates (illustration) 13-3
minor updates (illustration) 13-3
patch releases (illustration) 13-3
service packs (illustration) 13-3
IPv6 described B-11
J
Java Plug-in
Linux 1-43, C-57
Solaris 1-43, C-57
Windows 1-42, C-56
K
KBs
comparing 7-42, 12-15
default filename 7-13
deleting 7-43, 12-16
described 7-3
downloading 7-45, 12-18
histogram 7-12
initial baseline 7-3
learning accept mode 7-13
loading 7-43, 12-16
monitoring 7-40, 12-13
renaming 7-44, 12-17
saving 7-43, 12-16
scanner threshold 7-12
tree structure 7-12
uploading 7-46, 12-19
Knowledge Base see KB
Known Host Keys pane
configuring 2-16
described 2-16
field descriptions 2-16
L
Learned OS pane
clearing 6-37, 12-10
described 6-37, 12-10
field descriptions 6-37, 12-10
passive OS fingerprinting 6-37, 12-10
learned OS values
clearing 6-37, 12-10
deleting 6-37, 12-10
user roles 6-36, 12-10
learning accept mode
anomaly detection 7-3
configuring 7-13
user roles 7-13
Learning Accept Mode tab
described 7-13
field descriptions 7-13
user roles 7-13
license key
installing 13-14
status 1-50, 13-9
trial 1-50, 13-9
licensing
described 1-50, 13-9
IPS device serial number 1-50, 13-9
Licensing pane
configuring 1-53, 13-12
described 1-50, 13-9
field descriptions 1-52
user roles 1-50
limitations on concurrent CLI sessions 1-43
listings UNIX-style 11-2
loading KBs 7-43, 12-16
LogApp
described A-2, A-18
functions A-18
syslog messages A-19
logging in
IDM 1-44, 1-45
terminal servers 14-16
LOKI
described B-45
protocol B-45
loose connections on sensors C-22
M
MainApp
applications A-5
described A-2
host statistics A-5
responsibilities A-5
show version command A-5
maintenance partition
configuring
IDSM-2 (Catalyst software) 14-39
IDSM-2 (Cisco IOS software) 14-43
described A-3
major updates described 13-3
managing rate limiting 9-13, 12-9
manual block to bogus host C-42
master blocking sensor
described 9-28
not set up properly C-43
Master Blocking Sensor pane
configuring 9-29
described 9-28
field descriptions 9-28
Master engine
alert frequency B-5
alert frequency parameters (table) B-5
described B-3
event actions B-6
general parameters (table) B-4
promiscuous delta B-5
universal parameters B-4
memory for IDM 1-42, C-56
merging configuration files C-2
Meta engine
described 5-24, B-13
parameters (table) B-14
Signature Event Action Processor 5-24, B-13
Meta Event Generator described 6-32
MIBs supported 8-6, C-19
minor updates described 13-4
Miscellaneous tab
configuring
application policy 5-67
IP fragment reassembly mode 5-71
IP logging 5-80
TCP stream reassembly mode 5-78
described 5-57
field descriptions 5-58
user roles 5-57
modes
anomaly detection detect 7-3
anomaly detection inactive 7-3
anomaly detection learning accept 7-3
Bypass 3-26
Inline Interface Pair 3-13
inline VLAN pair 3-13
promiscuous 3-12
VLAN groups 3-13
modify packets inline modes 4-3
monitoring
events 6-35
KBs 7-40, 12-13
Viewer privileges A-26
moving OS maps 6-29
Multi String engine
described B-14
parameters (table) B-15
Regex B-14
N
Neighborhood Discovery
options B-11
types B-11
Network Blocks pane
configuring 9-34, 12-6
described 9-34, 12-5
field descriptions 9-34, 12-5
user roles 9-34, 12-5
Network pane
configuring 2-3
described 2-2
field definitions 2-2
TLS/SSL 2-3
user roles 2-2
Network Timing Protocol see NTP
never block
hosts 9-7
networks 9-7
NM-CIDS
bootloader
described 14-33
file 14-33
initializing 1-28
password recovery 2-7, C-10
reimaging 14-30, 14-31
setup command 1-28
system image file 14-30
time sources 2-24, C-15
upgrading the bootloader 14-33
Normalizer engine
described B-16
IP fragment reassembly B-16
parameters (table) B-18
TCP stream reassembly B-16
NotificationApp
alert information A-8
described A-3
functions A-8
SNMP gets A-8
SNMP traps A-8
statistics A-10
system health information A-9
NTP
authenticated 2-30
configuring servers 2-29
described 2-23, C-14
incorrect configuration C-16
sensor time source 2-29, 2-30
time synchronization 2-23, C-14
unauthenticated 2-30
O
obtaining
cryptographic account 13-2
IPS software 13-1
operation settings
configuring 7-11
user roles 7-10
Operation Settings tab
described 7-10
field descriptions 7-10
user roles 7-10
Operator privileges A-26
OS Identifications tab
described 6-26
field descriptions 6-27
OS maps
adding 6-29
configuring 6-29
deleting 6-29
editing 6-29
moving 6-29
Other Protocols tab
described 7-26, 7-34
describing 7-18, 7-26
enabling other protocols 7-18
external zone 7-34
field descriptions 7-18, 7-34
illegal zone 7-26
P
partitions
application A-3
maintenance A-3
recovery A-3
passive OS fingerprinting
configuring 6-27
described 6-25
components 6-26
password recovery
AIP-SSM 2-8, C-11
appliances 2-5, C-8
described 2-4, C-7
disabling 2-9, C-12
GRUB menu 2-5, C-8
IDSM-2 2-7, C-10
IPS-4240 2-6, C-9
IPS-4255 2-6, C-9
NM-CIDS 2-7, C-10
platforms 2-4, C-7
ROMMON 2-6, C-9
troubleshooting 2-10, C-13
verifying 2-10, C-13
patch releases described 13-4
peacetime learning and anomaly detection 7-3
physical connectivity issues C-30
physical interfaces configuration restrictions 3-9
platforms and concurrent CLI sessions 1-43
policies and platform limitations 5-2, 6-11, 7-8
Post-Block ACLs 9-20, 9-21
Pre-Block ACLs 9-20, 9-21
prerequisites for blocking 9-5
promiscuous delta
calculating risk rating 6-3
described 6-3
promiscuous mode
described 3-12
packet flow 3-12
protocols
ARP B-10
CIDEE A-32
DCE B-28
DDoS B-45
H.323 B-23
H225.0 B-23
IDAPI A-28
IDCONF A-31
IDIOM A-30
IPv6 B-11
LOKI B-45
MSSQL B-29
Neighborhood Discovery B-11
Q.931 B-23
RDEP2 A-29
RPC B-28
SDEE A-31
Q
Q.931 protocol
described B-23
SETUP messages B-23
quarantined IP address events described 10-2
R
rate limiting
ACLs 9-5
configuring 9-13, 12-9
described 9-4, 12-7
managing 9-13, 12-9
percentages 9-12, 12-7
routers 9-4, 12-7
service policies 9-5
supported signatures 9-4, 12-7
Rate Limits pane
described 9-12, 12-7
field descriptions 9-12, 12-8
RDEP2
described A-29
functions A-29
messages A-29
responsibilities A-29
rebooting the sensor 11-5
Reboot Sensor pane
button functions 11-5
configuring 11-5
described 11-5
user roles 11-5
recover command 14-13
recovering
AIP-SSM C-67
application partition image 14-13
recovery/upgrade CD 14-29
recovery partition
described A-3
upgrading 14-6
reimaging
AIP-SSM 14-51
appliances 14-13
described 14-1
IDS-4215 14-17
IDSM-2 14-36
IPS-4240 14-21
IPS-4255 14-21
IPS-4260 14-25
IPS 4270-20 14-27
NM-CIDS 14-31
sensors 13-8, 14-1
removing the last applied upgrade 14-12
Rename Knowledge Base dialog box
field descriptions 7-44, 12-17
user roles 7-44, 12-17
renaming KBs 7-44, 12-17
reset not occurring for a signature C-50
resetting AIP-SSM C-67
Restore Defaults pane
button functions 11-4
configuring 11-4
described 11-4
user roles 11-4
restoring
current configuration C-4
defaults 11-4
retrieving events through RDEP2 (illustration) A-29
risk rating
calculating 6-2
described 6-25
example 6-11
ROMMON
described 14-15
IDS-4215 14-17
IPS-4240 14-21
IPS-4255 14-21
IPS-4260 14-25
IPS-4270 14-25
IPS 4270-20 14-27
password recovery 2-6, C-9
remote sensors 14-15
serial console port 14-15
TFTP 14-15
round-trip time see RTT
Router Blocking Device Interfaces pane
configuring 9-23
described 9-20
field descriptions 9-22
RPC portmapper B-30
RTT
described 14-15
TFTP limitation 14-15
rules0 event action rules default policy 6-11
rules0 pane
default 6-13
described 6-13
tabs 6-13
S
Save Knowledge Base dialog box
described 7-42, 12-15
field descriptions 7-42, 12-15
user roles 7-42, 12-15
saving KBs 7-43, 12-16
scheduling automatic upgrades 14-9
SDEE
defined A-31
HTTP A-31
protocol A-31
server requests A-31
security and SSH 2-13
security information on Cisco Security Center 13-16
security policies described 5-1, 6-1, 7-1
sending commands through RDEP2 (illustration) A-30
sensing interfaces
described 3-3
modes 3-3
PCI cards 3-3
sensor
blocking itself 9-8
not seeing packets C-33
process not running C-29
SensorApp
Alarm Channel A-23
Analysis Engine A-23
described A-3
packet flow A-23
processors A-22
responsibilities A-22
Signature Event Action Handler A-22, A-24
Sensor Key pane
button functions 2-18
described 2-17
field descriptions 2-18
sensor SSH key
displaying 2-18
generating 2-18
user roles 2-17
sensors
access problems C-24
asymmetric traffic and disabling anomaly detection C-19
configuring to use NTP 2-30
corrupted SensorApp configuration C-35
diagnostics reports 11-9
disaster recovery C-6
downgrading 14-12
incorrect NTP configuration C-16
initializing 1-3, 2-1
interface support 3-4
IP address conflicts C-27
license 1-53, 13-12
loose connections C-22
misconfigured access lists C-26
no alerts C-32, C-59
not seeing packets C-33
NTP time source 2-30
NTP time synchronization 2-23, C-14
partitions A-3
physical connectivity C-30
preventive maintenance C-2
rebooting 11-5
recovering the system image 13-8
reimaging 13-8, 14-1
restoring defaults 11-4
sensing process not running C-29
setting up 2-1
setup command 1-3, 1-6, 2-1
shutting down 11-6
statistics 11-10
system images 13-8
system information 11-11
time sources 2-23, C-14
troubleshooting software upgrades C-55
updating 11-3, 11-7
using NTP time source 2-29
serial number and the show inventory command C-69
Server Certificate pane
button functions 2-22
certificate
displaying 2-22
generating 2-22
described 2-21
field descriptions 2-22
user roles 2-21
service account
creating C-5
described A-27, C-4
privileges A-26
TAC A-27
troubleshooting A-27
Service DNS engine
described B-19
parameters (table) B-19
Service engine
described B-18
Layer 5 traffic B-18
Service FTP engine
described B-20
parameters (table) B-21
PASV port spoof B-20
Service Generic Advanced engine described B-22
Service Generic engine
described B-21
parameters (table) B-22
Service H225 engine
ASN.1PER validation B-23
described B-23
features B-23
parameters (table) B-24
TPKT validation B-23
Service HTTP engine
custom signature 5-52
described 5-52, B-25
example signature 5-52
parameters (table) B-26
Service IDENT engine
described B-27
parameters (table) B-27
Service MSRPC engine
DCS/RPC protocol B-28
described B-28
parameters (table) B-28
Service MSSQL engine
described B-29
MSSQL protocol B-29
parameters (table) B-29
Service NTP engine
described B-29
parameters (table) B-29
service packs described 13-4
Service privileges A-26
service role 2-34, A-27
Service RPC engine
described B-29
parameters (table) B-29, B-30
RPC portmapper B-30
Service SMB Advanced engine
described B-32
parameters (table) B-33
Service SMB engine
described B-31
parameters (table) B-31
Service SNMP engine
described B-34
parameters (table) B-35
Service SSH engine
described B-35
parameters (table) B-35
Service TNS engine
described B-36
parameters (table) B-36
setting
current KBs 7-43, 12-16
system clock 2-32
setting up
sensors 2-1
terminal servers 14-16
setup command 1-3, 1-6, 1-14, 1-21, 1-28, 1-33, 2-1
show events command C-87, C-88
show interfaces command C-86
show inventory command C-69
show module 1 details command C-66
show settings command 2-10, C-13
show statistics command C-76
show statistics virtual-sensor command C-23, C-76
show tech-support command
described C-70
output C-71
show version command C-73
Shut Down Sensor pane
button functions 11-5
configuring 11-6
described 11-5
user roles 11-5
shutting down the sensor 11-6
sig0 pane
default 5-3
described 5-3
tabs 5-3
signature/virus update files described 13-5
Signature Configuration tab
described 5-4
field descriptions 5-5
signatures
adding 5-14
assigning actions 5-18
cloning 5-15
disabling 5-13
enabling 5-13
tuning 5-17
signature definition policies
adding 5-2
cloning 5-2
default policy 5-2
deleting 5-2
sig0 5-2
Signature Definitions pane
described 5-2
field descriptions 5-2
signature engines
AIC 5-60, B-8
Atomic B-9
Atomic ARP B-10
Atomic IP B-10
Atomic IPv6 B-11
creating custom signatures 5-28
described B-1
event actions B-6
Flood B-12
Flood Host B-12
Flood Net B-13
list B-2
Meta 5-24, B-13
Multi String B-14
Normalizer B-16
Service B-18
Service DNS B-19
Service FTP B-20
Service Generic B-21
Service Generic Advanced B-22
Service H225 B-23
Service HTTP 5-52, B-25
Service IDENT B-27
Service MSRPC B-28
Service MSSQL B-29
Service NTP engine B-29
Service RPC B-29
Service SMB B-31
Service SMB Advanced B-32
Service SNMP B-34
Service SSH engine B-35
Service TNS B-36
State B-37
String 5-50, B-38
supported by IDM 5-27, 5-43
Sweep B-41
Sweep Other TCP B-43
Traffic Anomaly 7-5, B-43
Traffic ICMP B-45
Trojan B-46
signature engine update files described 13-5
Signature Event Action Filter
described 6-6
parameters 6-6, A-24
Signature Event Action Handler
alarm channel 6-5, A-24
components 6-5, A-24
described 6-6, A-24
figure 6-6, A-25
Signature Event Action Override described 6-6, A-24
Signature Event Action Processor
described 6-5, A-22
flow of signature events 6-6, A-25
signature fidelity rating
calculating risk rating 6-2
described 6-2
signatures
adding 5-14
alert frequency 5-21
assigning actions 5-18
cloning 5-16
custom 5-4
default 5-4
described 5-3
disabling 5-13
editing 5-17
enabling 5-13
false positives 5-3
no TCP reset C-50
rate limits 9-4, 12-7
subsignatures 5-4
tuned 5-4
tuning 5-17
signature variables
adding 5-56
deleting 5-56
described 5-55
editing 5-56
Signature Variables tab
configuring 5-56
field descriptions 5-56
Signature Wizard unsupported signature engines 5-27, 5-43
SNMP
configuring 8-2
described 8-1
Get 8-1
GetNext 8-1
Set 8-1
supported MIBs 8-6, C-19
Trap 8-1
SNMP General Configuration pane
configuring 8-2
described 8-2
field descriptions 8-2
user roles 8-2
SNMP traps
configuring 8-4
described 8-1
SNMP Traps Configuration pane
configuring 8-4
field descriptions 8-4
software architecture
ARC (illustration) A-12
IDAPI (illustration) A-28
RDEP2 (illustration) A-29
software bypass
supported configurations 3-11
with hardware bypass 3-11
software downloads Cisco.com 13-1
software file names
recovery (illustration) 13-5
signature/virus updates (illustration) 13-4
signature engine updates (illustration) 13-5
system image (illustration) 13-5
software release examples
platform-dependent 13-7
platform identifiers 13-7
platform-independent 13-6
software updates
supported FTP servers 14-2
supported HTTP/HTTPS servers 14-2
SPAN port issues C-30
SSH
described 2-13
security 2-13
SSH Server
private keys A-20
public keys A-20
standards
CIDEE A-32
SDEE A-31
State engine
Cisco Login B-37
described B-37
LPR Format String B-37
parameters (table) B-37
SMTP B-37
statistics display 11-10
Statistics pane
button functions 11-10
categories 11-9
described 11-9
user roles 11-9
using 11-10
String engine described 5-50, B-38
String ICMP engine parameters (table) B-38
String TCP engine
custom signature 5-50
example signature 5-50
parameters (table) B-39
String UDP engine parameters (table) B-40
subinterface 0 described 3-14
subsignatures described 5-4
summarization
described 6-5
Fire All 6-5
Fire Once 6-5
Global Summarization 6-5
Meta engine 6-5
Summary 6-5
Summarizer described 6-32
Summary pane
described 3-15
field descriptions 3-15
supported
FTP servers 14-2
HTTP/HTTPS servers 14-2
IDSM-2 configurations C-61
IPS interfaces for CSA MC 10-4
Sweep engine
described B-40, B-41
parameters (table) B-41, B-43
Sweep Other TCP engine described B-43
switch commands for troubleshooting C-61
system architecture
directory structure A-32
supported platforms A-1
system clock setting 2-32
system components (IDAPI) A-28
System Configuration Dialog
described 1-3
example 1-4
system design (illustration) A-1
system images
installing IPS-4240 14-21
installing IPS-4255 14-21
sensors 13-8
system information display 11-11
System Information pane
button functions 11-11
described 11-10
user roles 11-11
using 11-11
system resources status and the Home window 1-2
T
TAC
service account A-27, C-4
show tech-support command C-70
target value rating
adding 6-18
calculating risk rating 6-3
configuring 6-18
deleting 6-18
described 6-3, 6-17
editing 6-18
Target Value Rating tab
configuring 6-18
field descriptions 6-18
TCP fragmentation described B-16
TCP Protocol tab
described 7-15, 7-24, 7-31
enabling TCP 7-15
external zone 7-31
field descriptions 7-15, 7-24, 7-31
illegal zone 7-24
TCP reset interfaces
conditions 3-8
described 3-7
list 3-7
TCP resets not occurring C-50
TCP stream reassembly
described 5-73
mode 5-78
parameters (table) 5-73
signatures (table) 5-73
terminal servers setup 14-16
testing fail-over 3-11
TFN2K
described B-45
Trojans B-46
TFTP and RTT 14-15
TFTP servers
recommended
UNIX 14-15
Windows 14-15
threat rating described 6-4
Thresholds for KB Name window
described 7-40, 12-13
field descriptions 7-40, 12-13
filtering information 7-40, 12-13
user roles 7-40, 12-13
time correction on the sensor 2-28, C-17
Time pane
configuring 2-27
described 2-23
field descriptions 2-25, 2-26
user roles 2-23
time sources
AIM-IPS 2-24, C-15
AIP-SSM 2-24, C-15
appliances 2-23, C-14
IDSM-2 2-23, C-14
NM-CIDS 2-24, C-15
time synchronization and IPS modules 2-25, C-16
TLS
certificates 1-47, 2-18
handshaking 1-47, 2-19
understanding 1-47, 2-3, 2-18
Traffic Anomaly engine
described 7-5, B-43
protocols 7-5, B-43
signatures 7-5, B-43
traffic flow notifications
configuring 3-28
overview 3-27
Traffic Flow Notifications pane
configuring 3-28
field descriptions 3-27
Traffic ICMP engine
DDoS B-45
described B-45
LOKI B-45
parameters (table) B-45
TFN2K B-45
Transport Layer Security see TLS
trial license key 1-50, 13-9
Tribe Flood Network 2000 see TFN2K
Tribe Flood Network see TFN
Trojan engine
BO2K B-46
described B-46
TFN2K B-46
Trojans
BO B-46
BO2K B-46
LOKI B-45
TFN2K B-46
troubleshooting
AIP-SSM
commands C-66
debugging C-67
recovering C-67
reset C-67
Analysis Engine busy C-58
applying software updates C-53
ARC
blocking not occurring for signature C-42
device access issues C-39
enabling SSH C-42
inactive state C-38
misconfigured master blocking sensor C-43
verifying device interfaces C-41
automatic updates C-54
cannot access sensor C-24
cidDump C-91
cidLog messages to syslog C-49
communication C-24
corrupted SensorApp configuration C-35
debug logger zone names (table) C-49
debug logging C-44
disaster recovery C-6
duplicate sensor IP addresses C-27
enabling debug logging C-45
external product interfaces 10-11, C-22
faulty DIMMs C-36
gathering information C-69
IDM
cannot access sensor C-58
will not load C-57
IDSM-2
command and control port C-64
diagnosing problems C-60
not online C-64
serial cable C-66
status indicator C-62
switch commands C-61
TCP reset port C-66
IPS modules and time drift 2-25, C-16
manual block to bogus host C-42
misconfigured access list C-26
no alerts C-32, C-59
NTP C-50
password recovery 2-10, C-13
physical connectivity issues C-30
preventive maintenance C-2
reset not occurring for a signature C-50
sensing process not running C-29
sensor events C-87
sensor loose connections C-22
sensor not seeing packets C-33
sensor software upgrade C-55
service account C-4
show events command C-87
show interfaces command C-85, C-86
show statistics command C-76
show tech-support command C-70, C-71
show version command C-73
software upgrade
IDS-4235 C-52
IDS-4250 C-52
software upgrades C-52
SPAN port issue C-30
upgrading from 5.x to 6.0 C-52
verifying Analysis Engine is running C-20
verifying ARC status C-37
Trusted Hosts pane
configuring 2-20
described 2-20
field definitions 2-20
tuned signatures described 5-4
tuning
AIC signatures 5-68
IP fragment reassembly signatures 5-72
signatures 5-17
U
UDP Protocol tab
described 7-16, 7-25, 7-32
enabling UDP 7-16
external zone 7-32
field descriptions 7-17, 7-33
illegal zone 7-25
unassigned VLAN groups described 3-14
unauthenticated NTP 2-30
understanding
SSH 2-13
time on the sensor 2-23, C-14
UNIX-style directory listings 11-2
Update Sensor pane
configuring 11-7
described 11-6
field descriptions 11-6
user roles 11-6
updating
Cisco.com 11-6
FTP server 11-6
sensors 11-7
upgrade
command 14-3
files 14-3
upgrade command 14-6
upgrading
5.x to 6.0 13-8
files 14-3
from 5.x to 6.0 C-52
maintenance partition
IDSM-2 (Catalyst software) 14-46
IDSM-2 (Cisco IOS software) 14-47
minimum required version 13-8
recovery partition 14-6, 14-13
uploading KBs
FTP 7-45, 12-18
SCP 7-45, 12-18
Upload Knowledge Base to Sensor dialog box
described 7-45, 12-18
field descriptions 7-45, 12-18
user roles 7-45, 12-18
URL for Cisco Security Center 13-16
user roles
Administrator A-26
Operator A-26
Service A-26
Viewer A-26
Users pane
configuring 2-35
described 2-33
field definitions 2-35
user roles 2-34
using
debug logging C-44
TCP reset interface 3-8
V
VACLs
described 9-2
Post-Block 9-25
Pre-Block 9-25
verifying
installation
AIM-IPS C-69
NME-IPS C-69
password recovery 2-10, C-13
sensor initialization 1-39
sensor setup 1-39
Viewer privileges A-26
viewing
IP logs 12-21
statistics 11-10
system information 11-11
virtual sensors
adding 4-5
default virtual sensor 4-2, 4-4
deleting 4-5
described 4-1, 4-4
editing 4-5
stream segregation 4-3
Virtual Sensors pane
described 4-4
field descriptions 4-4
VLAN groups
802.1q encapsulation 3-14
configuration restrictions 3-10
configuring 3-24
deploying 3-23
described 3-13
switches 3-23
VLAN Groups pane
configuring 3-24
described 3-23
field descriptions 3-24
VLAN IDs 3-23
VLAN pairs configuration 3-22
VLAN Pairs pane
configuring 3-22
field descriptions 3-21
overview 3-21
W
watch list rating
calculating risk rating 6-3
described 6-3
Web Server
described A-3, A-21
HTTP 1.0 and 1.1 support A-21
private keys A-20
public keys A-20
RDEP2 support A-21
worms
attacks and histograms 7-12
Blaster 7-2
Code Red 7-2
described 7-2
Nimbda 7-2
protocols 7-2
Sasser 7-2
scanners 7-2
Slammer 7-2
SQL Slammer 7-2
Z
zones
external 7-4
illegal 7-4
internal 7-4