Table Of Contents
Numerics - A - B - C - D - E - F - G - H - I - K - L - M - N - O - P - Q - R - S - T - U - V - W - Z
Index
Numerics
4GE bypass interface card
configuration restrictions 5-10
described 5-10
802.1q encapsulation for VLAN groups 5-14
A
accessing IPS software 20-2
access lists
misconfiguration C-26
necessary hosts 3-4
ACLs
adding 3-4
described 13-3
Post-Block 13-17, 13-18
Pre-Block 13-17, 13-18
Active Host Blocks pane
field descriptions 17-6
user roles 17-6
active update bulletins 20-10
ad0 pane
default 10-10
described 10-10
tabs 10-10
Add ACL Entry dialog box field descriptions 3-4
Add Active Host Block dialog box field descriptions 17-7
Add Allowed Host dialog box
field descriptions 4-5
user roles 4-5
Add Authorized Key dialog box
field descriptions 12-3
user roles 12-2
Add Blocking Device dialog box
field descriptions 13-15
user roles 13-14
Add Cat 6K Blocking Device Interface dialog box
field descriptions 13-23
user roles 13-22
Add Configured OS Map dialog box
field descriptions 6-25, 9-26
user roles 6-25, 9-23
Add Destination Port dialog box field descriptions 10-16
Add Device Login Profile dialog box
field descriptions 13-13
user roles 13-12
Add Event Action Filter dialog box
field descriptions 6-14, 9-15
user roles 6-13, 9-14
Add Event Action Override dialog box
field descriptions 6-11, 9-12
user roles 6-11, 9-12
Add Event Variable dialog box
field descriptions 6-29, 9-29
user roles 6-28, 9-28
Add External Product Interface dialog box
field descriptions 15-6
user roles 15-5
Add Histogram dialog box field descriptions 10-16
adding
ACLs 3-4
a host never to be blocked 13-11
anomaly detection policies 10-9
CSA MC interfaces 15-7
dashboards 2-1
denied attackers 17-5
event action filters 6-16, 9-17
event action overrides 9-13
event action rules policies 9-11
event variables 6-29, 9-30
external product interfaces 15-7
gadgets 2-1
host blocks 17-7
IPv4 target value rating 6-19, 9-20
IPv6 target value rating 6-22, 9-22
network blocks 17-9
OS maps 6-26, 9-27
risk categories 6-32, 9-33
signature definition policies 7-2
signatures 7-13
signature variables 7-27
virtual sensors 3-13, 6-11
Add Inline VLAN Pair dialog box field descriptions 3-10, 5-21
Add Interface Pair dialog box field descriptions 5-19
Add IP Logging dialog box field descriptions 17-14
Add IPv4 Target Value Rating dialog box
field descriptions 6-19, 9-19
user roles 6-18, 9-19
Add IPv6 Target Value Rating dialog box
field descriptions 6-21, 9-21
user roles 6-20, 9-21
Add Known Host Key dialog box
field descriptions 12-5
user roles 12-5
Add Master Blocking Sensor dialog box
field descriptions 13-26
user roles 13-25
Add Network Block dialog box field descriptions 17-9
Add Never Block Address dialog box
field descriptions 13-11
user roles 13-7
Add Policy dialog box field descriptions 7-2, 9-10, 10-9
Add Posture ACL dialog box field descriptions 15-7
Add Protocol Number dialog box field descriptions 10-18, 10-25
Add Rate Limit dialog box
field descriptions 17-11
user role 17-10
Address Resolution Protocol see ARP
Add Risk Level dialog box field descriptions 6-32, 9-32
Add Router Blocking Device Interface dialog box
field descriptions 13-20
user roles 13-17
Add Signature dialog box field descriptions 7-7
Add Signature Variable dialog box
field descriptions 7-27
user roles 7-27
Add SNMP Trap Destination dialog box field descriptions 14-4
Add Trusted Host dialog box
field descriptions 12-10
user roles 12-9
Add User dialog box
field descriptions 4-18
user roles 4-17
Add Virtual Sensor dialog box
described 3-12, 6-9
field descriptions 3-13, 6-9
Add VLAN Group dialog box field descriptions 5-24
Advanced Alert Behavior Wizard
Alert Dynamic Response Fire All window field descriptions 8-26
Alert Dynamic Response Fire Once window field descriptions 8-27
Alert Dynamic Response Summary window field descriptions 8-27
Alert Summarization window field descriptions 8-26
Event Count and Interval window field descriptions 8-25
Global Summarization window field descriptions 8-28
AIC
policy 7-38
signatures (example) 7-39
AIC engine
AIC FTP B-8
AIC FTP engine parameters (table) B-9
AIC HTTP B-8
AIC HTTP engine parameters (table) B-9
described B-8
features B-8
signature categories 7-31
AIC policy enforcement
default configuration 7-32, B-8
described 7-32, B-8
sensor oversubscription 7-32, B-8
AIM-IPS
initializing 18-13
installing system image 21-22
logging in 19-5
session command 19-5
sessioning 19-4, 19-5
setup command 18-13
time sources 4-8, C-15
AIP-SSM
bypass mode 5-27
initializing 18-16
installing system image 21-26
logging in 19-6
password recovery 16-7, C-10
recovering C-66
reimaging 21-25
resetting C-65
session command 19-6
setup command 18-16
time sources 4-8, C-15
Alarm Channel described 9-6, A-25
alert and log actions (list) 9-7
alert behavior
normal 8-25
Signature Wizard 8-25
alert frequency
aggregation 7-19
configuring 7-19
controlling 7-19
modes B-5
Allowed Hosts/Networks pane
configuring 4-6
described 4-5
field descriptions 4-5
alternate TCP reset interface 5-8
Analysis Engine
described 6-2
error messages C-23
IDM exits C-55
verify it is running C-19
virtual sensors 6-2
anomaly detection
asymmetric traffic 10-2, 10-35
caution 10-2, 10-35
configuration sequence 10-5
default configuration (example) 10-4
described 10-2
detect mode 10-4
disabling C-18
event actions 10-6, B-62
inactive mode 10-4
learning accept mode 10-3
learning process 10-3
limiting false positives 10-13, 17-17
operation settings 10-11
protocols 10-3
signatures 10-6
signatures (table) 10-6, B-62
turning off 10-35
worms
attacks 10-12
described 10-3
zones 10-4
Anomaly Detection pane
button functions 17-17
described 17-16
field descriptions 17-17
user roles 17-16
anomaly detection policies
ad0 10-8
adding 10-9
cloning 10-9
default policy 10-8
deleting 10-9
Anomaly Detections pane
described 10-8
field descriptions 10-9
user roles 10-8
appliances
application partition image 21-12
GRUB menu 16-4, C-8
initializing 18-8
logging in 19-2
password recovery 16-4, C-8
terminal servers
described 19-3, 21-14
setting up 19-3, 21-14
time sources 4-7, C-14
UDLD protocol 5-22
upgrading recovery partition 21-5
Application Inspection and Control see AIC
application partition
described A-3
image recovery 21-12
application policy enforcement
described 7-32, B-8
disabled (default) 7-32, B-8
applying software updates C-52
ARC
ACLs 13-18, A-13
authentication A-14
blocking
application 13-2
connection-based A-16
not occurring for signature C-42
unconditional blocking A-16
block response A-13
Catalyst 6000 series switch
VACL commands A-18
VACLs A-18
Catalyst switches
VACLs A-15
VLANs A-15
checking status 13-3, 13-4
described A-3
design 13-2
device access issues C-39
enabling SSH C-41
features A-13
firewalls
AAA A-17
connection blocking A-17
NAT A-18
network blocking A-17
postblock ACL A-15
preblock ACL A-15
shun command A-17
TACACS+ A-18
formerly Network Access Controller 13-1
functions 13-2
illustration A-12
inactive state C-37
interfaces A-13
maintaining states A-16
managed devices 13-8
master blocking sensors A-13
maximum blocks 13-2
misconfigured master blocking sensor C-43
nac.shun.txt file A-16
NAT addressing A-14
number of blocks A-14
postblock ACL A-15
preblock ACL A-15
prerequisites 13-5
rate limiting 13-4
responsibilities A-12
single point of control A-14
SSH A-13
supported devices 13-6, A-15
Telnet A-13
troubleshooting C-36
VACLs A-13
verifying device interfaces C-41
verifying status C-36
ARP
Layer 2 signatures B-10
protocol B-10
ARP spoof tools
dsniff B-10
ettercap B-10
assigning actions to signatures 7-17
asymmetric traffic
anomaly detection 10-2, 10-35
disabling anomaly detection C-18
Atomic ARP engine
described B-10
parameters (table) B-10
Atomic IP Advanced engine
described B-11
restrictions B-12
Atomic IP engine
described 8-14, B-21
parameters (table) B-22
Atomic IPv6 engine
described B-25
ND protocol B-26
Neighborhood Discovery protocol B-25
signatures B-26
signatures (table) B-26
attack relevance rating
calculating risk rating 6-5, 9-3
described 6-5, 6-23, 9-3, 9-24
Attack Response Controller
described A-3
formerly known as Network Access Controller A-3
See ARC
attack severity rating
calculating risk rating 6-5, 9-3
described 6-5, 9-3
Audit mode
described 11-9
Test Global Correlation 11-9
authenticated NTP 4-7, 4-8, 4-9, 4-15, C-14, C-15
AuthenticationApp
authenticating users A-20
described A-3
login attempt limit A-20
method A-20
responsibilities A-19
secure communications A-20
sensor configuration A-19
Authorized Keys pane
configuring 12-3
described 12-2
field descriptions 12-2
RSA authentication 12-2
RSA key generation tool 12-3
Auto/Cisco.com Update pane
configuring 16-18
described 16-16
field descriptions 16-18
UNIX-style directory listings 16-17
user roles 16-16
automatic setup 18-2
automatic updates
Cisco.com 16-16
examples 21-10
information required 21-6
servers
FTP 16-16
SCP 16-16
troubleshooting C-53
autonegotiation for hardware bypass 5-11
auto-upgrade-option command 21-6
B
backing up
configuration C-2
current configuration C-4
BackOrifice 2000 see BO2K
BackOrifice see BO
basic setup 18-4
blocking
described 13-2
disabling 13-8
master blocking sensor 13-25
necessary information 13-3
not occurring for signature C-42
prerequisites 13-5
supported devices 13-6
types 13-2
Blocking Devices pane
configuring 13-15
described 13-14
field descriptions 13-15
ssh host-key command 13-15
Blocking Properties pane
adding a host never to be blocked 13-11
configuring 13-10
described 13-7
field descriptions 13-8
BO
described B-65
Trojans B-65
BO2K
described B-65
Trojans B-65
bypass mode
AIP-SSM 5-27
described 5-26
Bypass pane
field descriptions 5-26
user roles 5-26
C
calculating risk rating
attack relevance rating 6-5, 9-3
attack severity rating 6-5, 9-3
promiscuous delta 6-5, 9-3
signature fidelity rating 6-5, 9-3
target value rating 6-5, 9-3
watch list rating 6-6, 9-4
cannot access sensor C-24
Cat 6K Blocking Device Interfaces pane
configuring 13-23
described 13-22
field descriptions 13-23
CDP described 5-29
CDP Mode pane
configuring 5-29
field descriptions 5-29
user roles 5-29
certificates
displaying 12-11
Firefox 1-8
generating 12-11
IDM 1-7, 12-8
Internet Explorer 1-8
changing Microsoft IIS to UNIX-style directory listings 16-17
cidDump obtaining information C-91
CIDEE
defined A-33
example A-34
IPS extensions A-33
protocol A-33
supported IPS events A-33
cisco
default password 19-2
default username 19-2
Cisco.com
accessing software 20-2
Active Update Bulletins 20-10
downloading software 20-2
IPS software 20-1
software downloads 20-2
Cisco IOS rate limiting 13-4
Cisco IPS software files 21-2
Cisco Security Center
described 20-11
URL 20-11
Cisco Services for IPS
service contract 1-10, 16-11
supported products 1-10, 16-11
clear events command 4-13, 4-17, 17-4, C-17, C-90
Clear Flow States pane
described 17-28
field descriptions 17-28
clearing
events 4-17, 17-4, C-90
flow states 17-28
statistics C-76
clear password command 16-6, 16-7, C-9, C-11
CLI described A-3, A-29
client manifest described A-28
clock set command 4-16
Clone Event Action Rules dialog box field descriptions 9-10
Clone Policy dialog box field descriptions 7-2, 10-9
Clone Signature dialog box field descriptions 7-7
cloning
anomaly detection policies 10-9
event action rules policies 9-11
signature definition policies 7-2
signatures 7-15
CollaborationApp described A-3, A-27
command and control interface
described 5-2
list 5-2
commands
auto-upgrade-option 21-6
clear events 4-13, 4-17, 17-4, C-17, C-90
clear password 16-6, 16-7, C-9, C-11
clock set 4-16
copy backup-config C-3
copy current-config C-3
debug module-boot C-66
downgrade 21-11
hw-module module 1 reset C-65
hw-module module slot_number password-reset 16-7, C-10
session 19-5, 19-10
setup 4-1, 18-1, 18-4, 18-8, 18-13, 18-16, 18-20, 18-25
show events C-87
show health C-68
show settings 16-10, C-13
show statistics C-75
show statistics virtual-sensor C-23, C-75
show tech-support C-69
show version C-73
upgrade 21-3, 21-5
Compare Knowledge Bases dialog box field descriptions 17-19
comparing KBs 17-19, 17-21
component signatures
Meta engine B-31
risk rating B-31
configuration files
backing up C-2
merging C-2
configuration restrictions
alternate TCP reset interface 5-8
inline interface pairs 5-8
inline VLAN pairs 5-8
interfaces 5-8
physical interfaces 5-8
VLAN groups 5-9
Configure Summertime dialog box field descriptions 3-4, 4-11
configuring
AIC policy parameters 7-38
allowed hosts 4-6
allowed networks 4-6
anomaly detection operation settings 10-11
application policy 7-39
authorized keys 12-3
automatic upgrades 21-8
blocking devices 13-15
blocking properties 13-10
Cat 6K blocking device interfaces 13-23
CDP Mode 5-29
CPU, Memory, & Load gadget 2-12
CSA MC IPS interfaces 15-4
device login profiles 13-13
event action filters 6-16, 9-17
events 17-3
event variables 6-29, 9-30
external zone 10-31
general settings 6-34, 9-35
Global Correlation Health gadget 2-9
Global Correlation Reports gadget 2-7
host blocks 17-7
illegal zone 10-25
inline VLAN pairs 3-11
inspection/reputation 11-9
interface pairs 5-19
interfaces 5-17
Interface Status gadget 2-7
internal zone 10-18
IP fragment reassembly signatures 7-43
IP logging 17-15
IPv4 target value rating 6-19, 9-20
IPv6 target value rating 6-22
known host keys 12-6
learning accept mode 10-14
Licensing gadget 2-6
maintenance partition
IDSM-2 (Catalyst software) 21-30
IDSM-2 (Cisco IOS software) 21-34
master blocking sensor 13-26
network blocks 17-9
network participation 11-11
Network Security gadget 2-10
network settings 4-3
NTP servers 4-14
OS maps 6-26, 9-27
rate limiting 17-11
rate limiting devices 13-15
risk categories 6-32, 9-33
router blocking device interfaces 13-20
Sensor Health gadget 2-5
Sensor Information gadget 2-4
Sensor Setup window 3-5
sensor to use NTP 4-15
SNMP 14-2
SNMP traps 14-5
target value rating 9-22
TCP fragment reassembly parameters 7-50
time 4-11
Top Applications gadget 2-10
traffic flow notifications 5-28
trusted hosts 12-10
UDLD protocol 5-22
upgrades 21-4
users 4-19
VLAN groups 5-24
VLAN pairs 5-21
control transactions
characteristics A-8
request types A-8
cookies IDM 1-7
copy backup-config command C-3
copy current-config command C-3
correcting time on the sensor 4-13, C-17
CPU, Memory, & Load gadget
configuring 2-12
described 2-11
creating
Atomic IP Advanced signature 7-25
custom signatures
not using signature engines 8-3
Service HTTP 8-16
String TCP 8-21
using signature engines 8-1
IPv6 signatures 7-25
Meta signatures 7-21, 7-22
Post-Block VACLs 13-22
Pre-Block VACLs 13-22
service account C-5
cryptographic features (IDM) 1-1
CSA MC
adding interfaces 15-7
configuring IPS interfaces 15-4
host posture events 15-1, 15-4
quarantined IP address events 15-1
supported IPS interfaces 15-4
CtlTransSource
described A-2, A-11
illustration A-11
current configuration back up C-2
current KB setting 17-22
customizing
dashboards 2-1
gadgets 2-1
custom signatures
described 7-5
IPv6 signature 7-25
Meta signature 7-21
Custom Signature Wizard
no signature engine sequence 8-3
signature engine sequence 8-1
D
Dashboard pane gadgets 2-2
dashboards
adding 2-1
customizing 2-1
data structures (examples) A-7
DDoS
protocols B-64
Stacheldraht B-64
TFN B-64
debug logging enable C-45
debug-module-boot command C-66
default policies
ad0 10-8
sig0 7-2
defaults
KB filename 10-12
password 19-2
restoring 16-22
username 19-2
virtual sensor vs0 6-3
deleting
anomaly detection policies 10-9
event action filters 6-16, 9-17
event action overrides 9-13
event action rules policies 9-11
event variables 6-29, 9-30
imported OS values 17-27
IPv4 target value rating 6-19, 9-20
IPv6 target value rating 6-22, 9-22
KBs 17-23
learned OS values 17-26
OS maps 6-26, 9-27
risk categories 6-32, 9-33
signature definition policies 7-2
signature variables 7-27
virtual sensors 6-11
Denial of Service see DoS
denied attackers
adding 17-5
clearing list 17-5
hit count 17-4
resetting hit counts 17-5
Denied Attackers pane
described 17-4
field descriptions 17-5
user roles 17-4
using 17-5
deny actions (list) 9-8
detect mode (anomaly detection) 10-4
device access issues C-39
Device Login Profiles pane
configuring 13-13
described 13-12
field descriptions 13-12
devices 13-15
Diagnostics Report pane
button functions 17-30
described 17-30
user roles 17-30
using 17-31
diagnostics reports 17-31
Differences between knowledge bases KB_Name and KB_Name window field descriptions 17-20
disabling
anomaly detection C-18
blocking 13-8
global correlation 11-11
interfaces 5-17
password recovery 16-9, C-12
disaster recovery C-6
displaying
events C-88
health status C-69
password recovery setting 16-10, C-13
statistics C-76
tech support information C-70
version C-73
Distributed Denial of Service see DDoS
DoS tools B-5
downgrade command 21-11
downgrading sensors 21-11
downloading
KBs 17-24
software 20-2
Download Knowledge Base From Sensor dialog box
described 17-24
field descriptions 17-24
duplicate IP addresses C-27
E
Edit Actions dialog box field descriptions 7-9
Edit Allowed Host dialog box
field descriptions 4-5
user roles 4-5
Edit Authorized Key dialog box
field descriptions 12-3
user roles 12-2
Edit Blocking Device dialog box
field descriptions 13-15
user roles 13-14
Edit Cat 6K Blocking Device Interface dialog box
field descriptions 13-23
user roles 13-22
Edit Configured OS Map dialog box
field descriptions 6-25, 9-26
user roles 6-25, 9-23
Edit Destination Port dialog box field descriptions 10-16
Edit Device Login Profile dialog box
field descriptions 13-13
user roles 13-12
Edit Event Action Filter dialog box
field descriptions 6-14, 9-15
user roles 6-13, 9-14
Edit Event Action Override dialog box
field descriptions 6-11, 9-12
user roles 6-11, 9-12
Edit Event Variable dialog box
field descriptions 6-29, 9-29
user roles 6-28, 9-28
Edit External Product Interface dialog box
field descriptions 15-6
user roles 15-5
Edit Histogram dialog box field descriptions 10-16
editing
event action filters 6-16, 9-17
event action overrides 9-13
event variables 6-29, 9-30
interfaces 5-17
IPv4 target value rating 6-19, 9-20
IPv6 target value rating 6-22, 9-22
OS maps 6-26, 9-27
risk categories 6-32, 9-33
signatures 7-16
signature variables 7-27
virtual sensors 6-11
Edit Inline VLAN Pair dialog box field descriptions 3-10, 5-21
Edit Interface dialog box field descriptions 5-16
Edit Interface Pair dialog box field descriptions 5-19
Edit IP Logging dialog box field descriptions 17-14
Edit IPv4 Target Value Rating dialog box
field descriptions 6-19, 9-19
user roles 6-18, 9-19
Edit IPv6 Target Value Rating dialog box
field descriptions 6-21, 9-21
user roles 6-20, 9-21
Edit Known Host Key dialog box
field descriptions 12-5
user roles 12-5
Edit Master Blocking Sensor dialog box
field descriptions 13-26
user roles 13-25
Edit Never Block Address dialog box
field descriptions 13-11
user roles 13-7
Edit Posture ACL dialog box field descriptions 15-7
Edit Protocol Number dialog box field descriptions 10-18, 10-25
Edit Risk Level dialog box field descriptions 6-32, 9-32
Edit Router Blocking Device Interface dialog box
field descriptions 13-20
user roles 13-17
Edit Signature dialog box field descriptions 7-7
Edit Signature Variable dialog box
field descriptions 7-27
user roles 7-27
Edit SNMP Trap Destination dialog box field descriptions 14-4
Edit User dialog box
field descriptions 4-18
user roles 4-17
Edit Virtual Sensor dialog box
field descriptions 6-9
user roles 6-9
Edit VLAN Group dialog box field descriptions 5-24
efficacy
described 11-4
measurements 11-4
enabling
debug logging C-45
event action filters 6-16, 9-17
event action overrides 9-13
interfaces 5-17
Encryption Software Export Distribution Authorization 20-2
engines
AIC B-8
Fixed B-27
Flood B-30
Master B-4
Meta 7-21, B-31
Multi String B-33
Normalizer B-35
Service DNS B-37
Service FTP B-38
Service Generic B-39
Service H225 B-40
Service HTTP 8-15, B-43
Service IDENT B-45
Service MSRPC 8-12, B-45
Service MSSQL B-47
Service NTP B-47
Service P2P B-48
Service RPC 8-18, B-48
Service SMB Advanced B-50
Service SNMP B-52
Service SSH B-52
Service TNS B-53
State 8-19, B-55
String 8-20, 8-23, B-56
Sweep 8-24, B-59
Sweep Other TCP B-61
Traffic ICMP B-64
Trojan B-65
evAlert A-8
event action filters
adding 6-16, 9-17
configuring 6-16, 9-17
deleting 6-16, 9-17
described 6-13, 9-5
editing 6-16, 9-17
enabling 6-16, 9-17
Event Action Filters tab
configuring 6-16, 9-17
described 6-13, 9-14
field descriptions 6-13, 9-14
event action overrides
adding 9-13
deleting 9-13
described 6-4, 9-4
editing 9-13
enabling 9-13
risk rating range 6-4, 9-4
Event Action Overrides tab
described 9-12
field descriptions 9-12
event action rules
described 9-2
functions 9-2
Event Action Rules pane
described 9-10
field descriptions 9-10
user roles 9-10
event action rules policies
adding 9-11
cloning 9-11
deleting 9-11
events
displaying C-88
host posture 15-2
quarantined IP address 15-2
Events pane
configuring 17-3
described 17-2
field descriptions 17-2
Event Store
clearing events 4-13, C-17
data structures A-7
described A-2
examples A-7
responsibilities A-7
timestamp A-7
event types C-87
event variables
adding 6-29, 9-30
configuring 6-29, 9-30
deleting 6-29, 9-30
described 6-28, 9-28
editing 6-29, 9-30
Event Variables tab
configuring 6-29, 9-30
field descriptions 6-29, 9-29
Event Viewer window field descriptions 17-3
evError A-8
evLogTransaction A-8
evShunRqst A-8
evStatus A-8
example custom signatures
Atomic IP Advanced 7-25
Meta engine 7-22
external product interfaces
adding 15-7
described 15-1
issues 15-3, C-21
troubleshooting 15-10, C-21
trusted hosts 15-5
External Product Interfaces pane
described 15-5
field descriptions 15-5
external zone
configuring 10-31
protocols 10-29
user roles 10-29
External Zone tab
described 10-29
tabs 10-29
user roles 10-29
F
fail-over testing 5-10
false positives described 7-4
files
Cisco IPS 21-2
IDSM-2 password recovery 16-8, C-11
Firefox
certificates 1-8
validating CAs 1-8
Fixed engine described B-27
Fixed ICMP engine parameters (table) B-27
Fixed TCP engine parameters (table) B-28
Fixed UDP engine parameters (table) B-29
Flood engine described B-30
Flood Host engine parameters (table) B-30
Flood Net engine parameters (table) B-30
flow states clearing 17-28
FTP servers supported 16-16, 21-2
G
gadgets
adding 2-1
CPU, Memory, & Load 2-11
customizing 2-1
Dashboard pane 2-2
Global Correlation Health 2-8
Global Correlation Reports 2-7
IDM 2-2
IDM home pane 1-3
Interface Status 2-6
Licensing 2-5
Network Security 2-9
Sensor Health 2-4
Sensor Information 2-3
Top Applications 2-10
general settings
configuring 6-34, 9-35
described 6-33, 9-34
General tab
configuring 6-34, 9-35
described 6-33, 9-34, 10-15, 10-23
enabling zones 10-15, 10-23
field descriptions 6-34, 9-34
user roles 6-33, 9-34
generating diagnostics reports 17-31
global correlation
described 1-1, 11-1, 11-2, A-3
disabling 11-11
DNS server 11-6
error messages A-29
features 11-5
goals 11-5
health metrics 11-7
HTTP Proxy server 11-6
IPv6 support 6-20, 6-21, 6-29, 9-16, 9-21, 9-30, 11-6
license 1-10, 11-6, 11-8, 18-1, 18-5
Produce Alert 7-9, 9-8, 11-5, B-6
requirements 11-6
troubleshooting 11-12, C-20
update client (illustration) 11-8
update client described A-28
update server described A-28
Global Correlation Health gadget
configuring 2-9
described 2-8
Global Correlation Reports gadget
configuring 2-7
described 2-7
Global Variables pane field description 16-15
GRUB menu password recovery 16-4, C-8
H
H.225.0 protocol B-40
H.323 protocol B-40
hardware bypass
autonegotiation 5-11
configuration restrictions 5-10
fail-over 5-10
IPS-4260 5-10
IPS 4270-20 5-10
supported configurations 5-10
with software bypass 5-10
Home pane
device information 1-3
gadgets 1-3
health information 1-3
interface status 1-3
licensing information 1-3
system resources usage 1-3
updating 1-3
Host Blocks pane
configuring 17-7
described 17-6
host posture events
CSA MC 15-4
described 15-2
HTTP/HTTPS servers 16-16, 21-2
HTTP deobfuscation
ASCII normalization 8-15, B-43
described 8-15, B-43
hw-module module 1 reset command C-65
hw-module module slot_number password-reset command 16-7, C-10
I
IDAPI
communications A-3, A-31
described A-3
functions A-31
illustration A-31
responsibilities A-31
IDCONF
described A-32
example A-32
XML A-32
IDIOM
defined A-32
messages A-32
IDM
Analysis Engine is busy C-55
certificates 1-7, 12-8
cookies 1-7
cryptographic features 1-1
described 1-2, 1-5
gadgets 2-2
GUI 1-3
logging in 1-6
Signature Wizard supported signature engines 8-2
supported platforms 1-4
system requirements 1-4
TLS 1-7, 12-8
user interface 1-3
web browsers 1-2, 1-5
will not load C-55
IDSM-2
command and control port C-63
configuring
maintenance partition (Catalyst software) 21-30
maintenance partition (Cisco IOS software) 21-34
initializing 18-20
installing
system image (Catalyst software) 21-28
system image (Cisco IOS software) 21-29
logging in 19-8
password recovery 16-8, C-11
password recovery image file 16-8, C-11
reimaging 21-28
sessioning 19-8
setup command 18-20
supported configurations C-59
TCP reset port C-64
time sources 4-8, C-14
upgrading
maintenance partition (Catalyst software) 21-38
maintenance partition (Cisco IOS software) 21-39
illegal zone
configuring 10-25
user roles 10-22
Illegal Zone tab
described 10-22
user roles 10-22
IME time synchronization problems C-57
Imported OS pane
clearing 17-27
described 17-27
field descriptions 17-27
imported OS values
clearing 17-27
deleting 17-27
inactive mode (anomaly detection) 10-4
initializing
AIM-IPS 18-13
AIP-SSM 18-16
appliances 18-8
IDSM-2 18-20
NME-IPS 18-25
sensors 4-1, 18-1, 18-4
user roles 18-1
verifying 18-28
inline interface pair mode
configuration restrictions 5-8
described 5-13
Inline Interface Pair window
described 3-9
Startup Wizard 3-9
inline VLAN pair mode
configuration restrictions 5-8
configuring 3-11
described 5-13
supported sensors 5-13
UDLD protocol 5-22
Inline VLAN Pairs pane user roles 5-20
Inline VLAN Pairs window
described 3-10
field descriptions 3-10
Startup Wizard 3-10
Inspection/Reputation pane
configuring 11-9
described 11-8
field descriptions 11-9
installer
major version 20-6
minor version 20-6
installing
sensor license 1-12, 16-13
system image
AIM-IPS 21-22
AIP-SSM 21-26
IDSM-2 (Catalyst software) 21-28
IDSM-2 (Cisco IOS software) 21-29
IPS-4240 21-15
IPS-4255 21-15
IPS-4260 21-18
IPS 4270-20 21-20
NME-IPS 21-40
InterfaceApp described A-2
interface pairs
configuring 5-19
described 5-18
Interface Pairs pane
configuring 5-19
described 5-18
field descriptions 5-19
user roles 5-18
interfaces
alternate TCP reset 5-2
command and control 5-2
configuration restrictions 5-8
configuring 5-17
described 3-7, 5-1
disabling 5-17
editing 5-17
enabling 5-17
logical 3-7
physical 3-7
port numbers 5-1
sensing 5-2, 5-3
slot numbers 5-1
support (table) 5-4
TCP reset 5-6
VLAN groups 5-2
Interface Selection window
described 3-9
Startup Wizard 3-9
Interfaces pane
configuring 5-17
described 5-15
field descriptions 5-16
user roles 5-15
Interface Status gadget
configuring 2-7
described 2-6
Interface Summary window described 3-7
internal zone
configuring 10-18
user roles 10-15
Internal Zone tab
described 10-15
user roles 10-15
Internet Explorer validating certificates 1-8
IP fragmentation described B-35
IP fragment reassembly
configuring 7-42
described 7-40
mode 7-42
parameters (table) 7-40
signatures 7-43
signatures (example) 7-43
signatures (table) 7-40
IP logging
described 7-50, 17-13
event actions 17-13
system performance 17-13
IP Logging pane
configuring 17-15
described 17-13
field descriptions 17-14
user roles 17-13
IP Logging Variables pane described 16-15
IP logs
circular buffer 17-13
states 17-13
TCPDUMP 17-13
viewing 17-15
WireShark 17-13
IPS-4240
installing system image 21-15
password recovery 16-5, C-8
reimaging 21-15
IPS-4255
installing system image 21-15
password recovery 16-5, C-8
reimaging 21-15
IPS-4260
hardware bypass 5-10
installing system image 21-18
reimaging 21-18
IPS 4270-20
hardware bypass 5-10
installing system image 21-20
reimaging 21-20
IPS applications
internal communications A-31
summary A-35
table A-35
XML format A-2
IPS data
types A-8
XML document A-8
IPS events
evAlert A-8
evError A-8
evLogTransaction A-8
evShunRqst A-8
evStatus A-8
list A-8
types A-8
IPS modules
time synchronization 4-9, C-16
unsupported features 3-8
IPS Policies pane
described 6-8
field descriptions 6-9
IPS software
application list A-2
available files 20-1
configuring device parameters A-4
directory structure A-34
Linux OS A-1
obtaining 20-1
platform-dependent release examples 20-7
retrieving data A-4
security features A-5
tuning signatures A-4
updating A-4
user interaction A-4
versioning scheme 20-3
IPS software file names
major updates (illustration) 20-4
minor updates (illustration) 20-4
patch releases (illustration) 20-4
service packs (illustration) 20-4
IPv4 target value rating
adding 6-19, 9-20
configuring 6-19, 9-20
deleting 6-19, 9-20
editing 6-19, 9-20
IPv4 Target Value Rating tab
configuring 6-19, 9-20
field descriptions 6-19, 9-19
IPv6
described B-25
SPAN ports 5-12
switches 5-12
IPv6 target value rating
adding 6-22, 9-22
configuring 6-22, 9-22
deleting 6-22, 9-22
editing 6-22, 9-22
IPv6 Target Value Rating tab
configuring 6-22, 9-22
field descriptions 6-21, 9-21
K
KBs
comparing 17-21
default filename 10-12
deleting 17-23
described 10-3
downloading 17-24
histogram 10-12, 17-16
initial baseline 10-3
learning accept mode 10-12
loading 17-22
monitoring 17-19
renaming 17-23
saving 17-22
scanner threshold 10-12, 17-16
tree structure 10-12, 17-16
uploading 17-25
Knowledge Base see KB
Known Host Keys pane
configuring 12-6
describing 12-5
field descriptions 12-5
L
Learned OS pane
clearing 17-26
described 17-26
field descriptions 17-26
learned OS values
clearing 17-26
deleting 17-26
learning accept mode (anomaly detection) 10-3
Learning Accept Mode tab
configuring 10-14
described 10-12
field descriptions 10-13
user roles 10-12
license files
BSD license D-3
expat license D-12
GNU Lesser license D-22
GNU license D-17
license key trial 1-10, 16-11
licensing
described 1-10, 16-10
IPS device serial number 1-10, 16-10
Licensing gadget
configuring 2-6
described 2-5
Licensing pane
configuring 1-12, 16-13
described 1-10, 16-10
field descriptions 1-12, 16-12
user roles 1-12, 16-10
limitations for concurrent CLI sessions 19-1
listings UNIX-style 16-17
loading KBs 17-22
Logger
described A-3, A-19
functions A-19
syslog messages A-19
logging in
AIM-IPS 19-5
AIP-SSM 19-6
appliances 19-2
IDM 1-6
IDSM-2 19-8
NME-IPS 19-10
sensors
SSH 19-11
Telnet 19-11
service role 19-2
terminal servers 19-3, 21-14
user role 19-1
LOKI
described B-64
protocol B-64
loose connections on sensors C-22
M
MainApp
components A-5
described A-2, A-5
host statistics A-6
responsibilities A-6
show version command A-6
maintenance partition
configuring
IDSM-2 (Catalyst software) 21-30
IDSM-2 (Cisco IOS software) 21-34
described A-3
major updates described 20-4
managing rate limiting 17-11
manifests
client A-28
server A-28
manual block to bogus host C-41
master blocking sensor
described 13-25
not set up properly C-43
Master Blocking Sensor pane
configuring 13-26
described 13-25
field descriptions 13-26
Master engine
alert frequency B-5
alert frequency parameters (table) B-5
described B-3
event actions B-6
general parameters (table) B-4
universal parameters B-4
merging configuration files C-2
Meta engine
component signatures B-31
described 7-21, B-31
parameters (table) B-32
Signature Event Action Processor 7-21, B-31
Meta Event Generator described 6-33, 9-34
MIBs supported 14-6, C-18
minor updates described 20-4
Miscellaneous tab
button functions 7-30
configuring
application policy 7-38
IP fragment reassembly mode 7-42
IP logging 7-51
TCP stream reassembly mode 7-49
described 7-29
field descriptions 7-30
user roles 7-29
modes
anomaly detection
detect 10-4
inactive 10-4
learning accept 10-3
bypass 5-26
inline interface pair 5-13
inline VLAN pair 5-13
promiscuous 5-11
VLAN Groups 5-13
modify packets inline modes 6-4
monitoring
events 17-3
KBs 17-19
moving OS maps 6-26, 9-27
Multi String engine
described B-33
parameters (table) B-33
Regex B-33
MySDN described 7-5
N
Neighborhood Discovery
options B-26
types B-26
Network Blocks pane
configuring 17-9
described 17-9
field descriptions 17-9
user roles 17-8
Network pane
configuring 4-3
described 4-2
field descriptions 4-2
TLS/SSL 4-4
user roles 4-2
network participation
data gathered 11-3
data use (table) 1-2, 11-2
described 11-3
health metrics 11-7
modes 11-4
requirements 11-4
statistics 11-4
Network Participation pane
configuring 11-11
described 11-10
field descriptions 11-11
Network Security gadget
configuring 2-10
described 2-9
network security health data resetting 17-29
Network Timing Protocol see NTP
never block
hosts 13-8
networks 13-8
NME-IPS
initializing 18-25
installing system image 21-40
logging in 19-10
reimaging 21-40
session command 19-10
sessioning 19-9, 19-10
setup command 18-25
time sources 4-8, C-15
Normalizer engine
described B-35
IP fragment reassembly B-35
parameters (table) B-36
TCP stream reassembly B-35
Normalizer mode described 6-4
NotificationApp
alert information A-9
described A-3
functions A-9
SNMP gets A-9
SNMP traps A-9
statistics A-10
system health information A-10
NTP
authenticated 4-7, 4-8, 4-9, 4-15, C-14, C-15
configuring servers 4-14
described 4-7, C-14
incorrect configuration 4-9, C-16
sensor time source 4-13, 4-15
time synchronization 4-7, C-14
unauthenticated 4-7, 4-8, 4-9, 4-15, C-14, C-15
verifying configuration 4-9
O
one-way TCP reset described 6-33, 9-34
Operation Settings tab
described 10-10
field descriptions 10-11
user roles 10-10
OS Identifications tab
described 6-25, 9-23
field descriptions 6-25, 9-25
OS maps
adding 6-26, 9-27
configuring 6-26, 9-27
deleting 6-26, 9-27
editing 6-26, 9-27
moving 6-26, 9-27
other actions (list) 9-9
Other Protocols tab
described 10-24, 10-31
describing 10-17
enabling other protocols 10-17
external zone 10-31
field descriptions 10-17, 10-31
illegal zone 10-24
P
P2P networks described B-48
partitions
application A-3
maintenance A-3
recovery A-3
Passive OS Fingerprinting
components 6-23, 9-24
configuring 6-24, 9-25
described 6-23, 9-24
password policy caution 16-2, 16-3
password recovery
AIP-SSM 16-6, C-10
appliances 16-4, C-8
CLI 16-9, C-12
described 16-3, C-7
disabling 16-9, C-12
GRUB menu 16-4, C-8
IDSM-2 16-8, C-11
IPS-4240 16-5, C-8
IPS-4255 16-5, C-8
platforms 16-3, C-7
ROMMON 16-5, C-8
troubleshooting 16-9, C-13
verifying 16-10, C-13
password requirements configuring 16-2
Passwords pane
described 16-2
field descriptions 16-2
patch releases described 20-5
peacetime learning (anomaly detection) 10-3
Peer-to-Peer see P2P
physical connectivity issues C-30
physical interfaces configuration restrictions 5-8
platforms concurrent CLI sessions 19-1
Post-Block ACLs 13-17, 13-18
Pre-Block ACLs 13-17, 13-18
prerequisites for blocking 13-5
promiscuous delta
calculating risk rating 6-5, 9-3
described 6-5, 9-3
promiscuous mode
described 5-11
packet flow 5-11
SPAN ports 5-12
VACL capture 5-12
protocols
ARP B-10
CIDEE A-33
DCE 8-12, B-46
DDoS B-64
H.323 B-40
H225.0 B-40
ICMPv6 B-11
IDAPI A-31
IDCONF A-32
IDIOM A-32
IPv6 B-25
LOKI B-64
MSSQL B-47
ND B-26
Neighborhood Discovery B-25, B-26
Q.931 B-41
RPC 8-12, B-46
SDEE A-33
Signature Wizard 8-11
UDLD 5-22
Q
Q.931 protocol
described B-41
SETUP messages B-41
quarantined IP address events described 15-2
R
rate limiting
ACLs 13-5
configuring 17-11
described 13-4
managing 17-11
percentages 17-10
routers 13-4
service policies 13-5
supported signatures 13-4
Rate Limits pane
described 17-10
field descriptions 17-11
rebooting the sensor 16-23
Reboot Sensor pane
configuring 16-23
described 16-23
user roles 16-23
recover command 21-11
recovering
AIP-SSM C-66
application partition image 21-12
recovery partition
described A-3
upgrading 21-5
reimaging
AIM-IPS 21-22
AIP-SSM 21-25
appliances 21-11
described 21-1
IDSM-2 21-28
IPS-4240 21-15
IPS-4255 21-15
IPS-4260 21-18
IPS 4270-20 21-20
NME-IPS 21-40
sensors 20-9, 21-1
removing
service packs 21-11
signature updates 21-11
Rename Knowledge Base dialog box field descriptions 17-23
renaming KBs 17-23
reputation
described 11-2
illustration 11-3
servers 11-3
Reset Network Security Health pane
described 17-29
field descriptions 17-29
user roles 17-29
resetting
AIP-SSM C-65
network security health data 17-29
Restore Default Interface dialog box field descriptions 3-8
Restore Defaults pane
configuring 16-23
described 16-22
user roles 16-22
restoring
current configuration C-4
defaults 16-23
risk categories
adding 6-32, 9-33
configuring 6-32, 9-33
deleting 6-32, 9-33
editing 6-32, 9-33
Risk Category tab
configuring 6-32, 9-33
described 6-31, 9-31
field descriptions 6-31, 9-32
risk rating
Alarm Channel 11-5
calculating 6-4, 9-2
component signatures B-31
described 6-23, 9-24
reputation score 11-4
ROMMON
described 21-13
IPS-4240 21-15
IPS-4255 21-15
IPS-4260 21-18
IPS 4270-20 21-18, 21-20
password recovery 16-5, C-8
remote sensors 21-13
serial console port 21-13
TFTP 21-14
round-trip time see RTT
Router Blocking Device Interfaces pane
configuring 13-20
described 13-17
field descriptions 13-19
RPC portmapper 8-18, B-48
RTT
described 21-14
TFTP limitation 21-14
rules0 pane
described 9-11
tabs 9-11
S
Save Knowledge Base dialog box
described 17-22
field descriptions 17-22
saving KBs 17-22
scheduling automatic upgrades 21-8
SDEE
described A-33
HTTP A-33
protocol A-33
server requests A-33
security information
Cisco Security Center 20-11
MySDN 7-5
security policies described 6-1, 7-1, 9-1, 10-1
security SSH 12-1
sensing interfaces
described 5-3
interface cards 5-3
modes 5-3
SensorApp
Alarm Channel A-23
Analysis Engine A-23
described A-3
event action filtering A-24
inline packet processing A-24
IP normalization A-24
packet flow A-25
processors A-22
responsibilities A-22
risk rating A-24
Signature Event Action Processor A-22, A-25
TCP normalization A-24
SensorBase Network
described 1-1, 11-1, 11-2, A-3
participation 1-1, 11-2
servers 1-2, 11-2
Sensor Health gadget
configuring 2-5
described 2-4
metrics 2-4
status 2-4
Sensor Health pane
described 16-14
field descriptions 16-14
Sensor Information gadget
configuring 2-4
described 2-3
Sensor Key pane
button functions 12-7
described 12-7
field descriptions 12-7
sensor SSH key
displaying 12-7
generating 12-7
user roles 12-7
sensors
access problems C-24
asymmetric traffic and disabling anomaly detection C-18
blocking self 13-8
configuring to use NTP 4-15
corrupted SensorApp configuration C-35
diagnostics reports 17-31
disaster recovery C-6
downgrading 21-11
incorrect NTP configuration 4-9, C-16
initializing 4-1, 18-1, 18-4
interface support 5-4
IP address conflicts C-27
license 1-12, 16-13
logging in
SSH 19-11
Telnet 19-11
loose connections C-22
misconfigured access lists C-26
no alerts C-31, C-57
not seeing packets C-33
NTP time source 4-15
NTP time synchronization 4-7, C-14
partitions A-3
physical connectivity C-30
preventive maintenance C-2
rebooting 16-23
recovering the application partition 21-11
recovering the system image 20-9
reimaging 20-9, 21-1
restoring defaults 16-23
sensing process not running C-28
setting up 4-1
setup command 4-1, 18-1, 18-4, 18-8
shutting down 16-24
statistics 17-32
system images 20-9
system information 17-32
time sources 4-7, C-14
troubleshooting software upgrades C-54
updating 16-18, 16-21
upgrading 21-4
using NTP time source 4-13
Sensor Setup window
described 3-2
Startup Wizard 3-2
Server Certificate pane
button functions 12-11
certificate
displaying 12-11
generating 12-11
described 12-11
field descriptions 12-11
user roles 12-11
server manifest described A-28
service account
creating C-5
described 4-18, A-30, C-4
TAC A-30
troubleshooting A-30
Service DNS engine
described B-37
parameters (table) B-37
Service engine
described B-37
Layer 5 traffic B-37
Service FTP engine
described B-38
parameters (table) B-39
PASV port spoof B-38
Service Generic engine
described B-39
parameters (table) B-40
Service H225 engine
ASN.1PER validation B-41
described B-40
features B-41
parameters (table) B-42
TPKT validation B-41
Service HTTP engine
custom signature 8-16
described 8-15, B-43
example signature 8-16
parameters (table) B-43
Service IDENT engine
described B-45
parameters (table) B-45
service-module ids-sensor slot/port session command 19-4, 19-9
Service MSRPC engine
DCS/RPC protocol 8-12, B-46
described 8-12, B-45
parameters (table) B-46
Service MSSQL engine
described B-47
MSSQL protocol B-47
parameters (table) B-47
Service NTP engine
described B-47
parameters (table) B-47
Service P2P engine described B-48
service packs described 20-4
service role 19-2, A-30
Service RPC engine
described 8-18, B-48
parameters (table) 8-18, B-48
RPC portmapper 8-18, B-48
Service SMB Advanced engine
described B-50
parameters (table) B-50
Service SNMP engine
described B-52
parameters (table) B-52
Service SSH engine
described B-52
parameters (table) B-53
Service TNS engine
described B-53
parameters (table) B-54
session command
AIM-IPS 19-5
AIP-SSM 19-6
IDSM-2 19-8
NME-IPS 19-10
sessioning
AIM-IPS 19-5
AIP-SSM 19-6
IDSM-2 19-8
NME-IPS 19-10
setting
current KB 17-22
system clock 4-17
setting up
sensors 4-1
terminal servers 19-3, 21-14
setup
automatic 18-2
command 4-1, 18-1, 18-4, 18-8, 18-13, 18-16, 18-20, 18-25
simplified mode 18-2
show events command C-87
show health command C-68
show interfaces command C-85
show settings command 16-10, C-13
show statistics command C-75
show statistics virtual-sensor command C-23, C-75
show tech-support command C-69
show version command C-72, C-73
Shut Down Sensor pane
configuring 16-24
described 16-24
user roles 16-24
shutting down the sensor 16-24
sig0 pane
default 7-3
described 7-3
field descriptions 7-6
signatures
assigning actions 7-17
cloning 7-14
tuning 7-16
tabs 7-3
signature/virus update files described 20-5
signature definition policies
adding 7-2
cloning 7-2
default policy 7-2
deleting 7-2
sig0 7-2
Signature Definitions pane
described 7-2
field descriptions 7-2
signature engines
AIC B-8
Atomic B-10
Atomic ARP B-10
Atomic IP 8-14, B-21
Atomic IP Advanced B-11
Atomic IPv6 B-25
creating custom signatures 8-1
described B-1
event actions B-6
Fixed B-27
Flood B-30
Flood Host B-30
Flood Net B-30
list B-2
Meta 7-21, B-31
Multi String B-33
Normalizer B-35
Service B-37
Service DNS B-37
Service FTP B-38
Service Generic B-39
Service H225 B-40
Service HTTP 8-15, B-43
Service IDENT B-45
Service MSRPC 8-12, B-45
Service MSSQL B-47
Service NTP engine B-47
Service P2P B-48
Service RPC 8-18, B-48
Service SMB Advanced B-50
Service SNMP B-52
Service SSH engine B-52
Service TNS B-53
State 8-19, B-55
String 8-20, 8-23, B-56
supported by IDM 8-2
Sweep Other TCP B-61
Traffic Anomaly B-62
Traffic ICMP B-64
Trojan B-65
signature engine update files described 20-6
Signature Event Action Filter
described 9-6, A-26
parameters 9-6, A-26
Signature Event Action Handler described 9-6, A-26
Signature Event Action Override described 9-6, A-25
Signature Event Action Processor
Alarm Channel 9-6, A-25
components 9-6, A-25
described 9-6, A-22, A-25
signature fidelity rating
calculating risk rating 6-5, 9-3
described 6-5, 9-3
signatures
adding 7-13
alert frequency 7-19
assigning actions 7-17
cloning 7-15
custom 7-5
default 7-4
described 7-4
editing 7-16
false positives 7-4
rate limits 13-4
subsignatures 7-4
TCP reset C-50
tuned 7-4
tuning 7-16
signature updates installation time 16-17
signature variables
adding 7-27
deleting 7-27
described 7-27
editing 7-27
Signature Variables tab
configuring 7-27
field descriptions 7-27
Signature Wizard
alert behavior 8-25
Alert Response window field descriptions 8-25
Atomic IP Engine Parameters window field descriptions 8-14
described 8-1
ICMP Traffic Type window field descriptions 8-13
Inspect Data window field descriptions 8-13
MSRPC Engine Parameters window field descriptions 8-12
protocols 8-11
Protocol Type window field descriptions 8-11
Service HTTP Engine Parameters window field descriptions 8-15
Service RPC Engine Parameters window field descriptions 8-18
Service Type window field descriptions 8-13
signature identification 8-11
Signature Identification window field descriptions 8-12
State Engine Parameters window field descriptions 8-19
String ICMP Engine Parameters window field descriptions 8-20
String TCP Engine Parameters window field descriptions 8-21
String UDP Engine Parameters window field descriptions 8-23
supported signature engines 8-2
Sweep Engine Parameters window field descriptions 8-24
TCP Sweep Type window field descriptions 8-14
TCP Traffic Type window field descriptions 8-13
UDP Sweep Type window field descriptions 8-13
UDP Traffic Type window field descriptions 8-13
using 8-4
Welcome window field descriptions 8-11
SNMP
configuring 14-2
described 14-1
Get 14-1
GetNext 14-1
Set 14-1
supported MIBs 14-6, C-18
Trap 14-1
SNMP General Configuration pane
configuring 14-2
described 14-2
field descriptions 14-2
user roles 14-2
SNMP traps
configuring 14-5
described 14-1
SNMP Traps Configuration pane
described 14-4
field descriptions 14-4
user roles 14-4
software architecture
ARC (illustration) A-12
IDAPI (illustration) A-31
software bypass
supported configurations 5-10
with hardware bypass 5-10
software downloads Cisco.com 20-2
software file names
recovery (illustration) 20-6
signature/virus updates (illustration) 20-5
signature engine updates (illustration) 20-6
system image (illustration) 20-6
software release examples
platform-dependent 20-7
platform identifiers 20-8
platform-independent 20-7
software updates
supported FTP servers 16-16, 21-2
supported HTTP/HTTPS servers 16-16, 21-2
SPAN port issues C-30
SSH
security 12-1
understanding 12-1
SSH Server
private keys A-20
public keys A-20
standards
CIDEE A-33
IDCONF A-32
SDEE A-33
Startup Wizard
access lists 3-4
adding virtual sensors 3-13
Add Virtual Sensor dialog box 3-12
described 3-1
Inline Interface Pair window
described 3-9
field descriptions 3-9
Inline VLAN Pairs window configuring 3-11
Interface Selection window 3-9
Interface Summary window 3-7
Sensor Setup window
configuring 3-5
field descriptions 3-2
Traffic Inspection Mode window 3-9
Virtual Sensors window
described 3-12
field descriptions 3-12
State engine
Cisco Login 8-19, B-55
described 8-19, B-55
LPR Format String 8-19, B-55
parameters (table) B-55
SMTP 8-19, B-55
Statistics pane
button functions 17-31
categories 17-31
described 17-31
using 17-32
statistics viewing 17-32
String engine described 8-20, 8-23, B-56
String ICMP engine parameters (table) B-57
String TCP engine
custom signature 8-21
example signature 8-21
parameters (table) B-57
String UDP engine parameters (table) B-58
subinterface 0 described 5-14
subsignatures described 7-4
summarization
described 6-6, 9-5
Fire All 6-7, 9-5
Fire Once 6-7, 9-6
Global Summarization 6-7, 9-5
Meta engine 6-7, 9-5
Summary 6-7, 9-5
Summarizer described 6-33, 9-34
Summary pane
button functions 5-15
described 5-14
field descriptions 3-8, 5-15
supported
FTP servers 16-16, 21-2
HTTP/HTTPS servers 16-16, 21-2
IDM platforms 1-4
IDSM-2 configurations C-59
IPS interfaces for CSA MC 15-4
Sweep engine
described 8-24, B-59
parameters (table) B-60, B-61
Sweep Other TCP engine described B-61
switch commands for troubleshooting C-60
system
clock setting 4-17
design (illustration) A-2
IDAPI components A-31
IDM requirements 1-4
system architecture
directory structure A-34
supported platforms A-1
System Configuration Dialog
described 18-2
example 18-3
system images
installing
AIM-IPS 21-22
AIP-SSM 21-26
IDSM-2 (Catalyst Software) 21-28
IDSM-2 (Cisco IOS Software) 21-29
IPS-4240 21-15
IPS-4255 21-15
IPS 4270-20 21-20
NME-IPS 21-40
sensors 20-9
System Information pane
described 17-32
using 17-32
system information viewing 17-32
T
TAC
service account 4-18, A-30, C-4
show tech-support command C-69
target value rating
calculating risk rating 6-5, 9-3
described 6-5, 6-18, 6-20, 9-3, 9-19, 9-21
TCP fragmentation described B-35
TCP Protocol tab
described 10-15, 10-23, 10-29
enabling TCP 10-15
external zone 10-29
field descriptions 10-16
illegal zone 10-23
TCP reset
described 5-6
IDSM-2 port C-64
interfaces (list) 5-7
not occurring C-50
not occurring for a signature C-50
TCP reset interfaces
conditions 5-7
described 5-6
TCP stream reassembly
described 7-44
mode 7-49
parameters (table) 7-44
signatures (table) 7-44
terminal server setup 19-3, 21-14
testing fail-over 5-10
TFN2K
described B-64
Trojans B-65
TFTP servers
recommended
UNIX 21-14
Windows 21-14
RTT 21-14
threat rating described 6-6, 9-4
Thresholds for KB Name window
described 17-18
field descriptions 17-18
filtering information 17-18
time
correcting on sensors 4-13, C-17
sensors 4-7, C-14
synchronization for IPS modules 4-9, C-16
Time pane
configuring 4-11
described 4-7
field descriptions 4-10
user roles 4-7
time sources
AIM-IPS 4-8, C-15
AIP-SSM 4-8, C-15
appliances 4-7, C-14
IDSM-2 4-8, C-14
NME-IPS 4-8, C-15
TLS
described 4-4
handshaking 1-7, 12-8
IDM 1-7, 12-8
Top Applications gadget
configuring 2-10
described 2-10
Traffic Anomaly engine
described B-62
protocols B-62
signatures B-62
traffic flow notifications
configuring 5-28
described 5-27
Traffic Flow Notifications pane
configuring 5-28
field descriptions 5-28
user roles 5-27
Traffic ICMP engine
DDoS B-64
described B-64
LOKI B-64
parameters (table) B-64
TFN2K B-64
Traffic Inspection Mode window described 3-9
Traps Configuration pane configuring 14-5
trial license key 1-10, 16-11
Tribe Flood Network 2000 see TFN2K
Tribe Flood Network see TFN
Trojan engine
BO2K B-65
described B-65
TFN2K B-65
Trojans
BO B-65
BO2K B-65
LOKI B-64
TFN2K B-65
troubleshooting C-1
AIP-SSM
debugging C-66
recovering C-66
reset C-65
Analysis Engine busy C-55
applying software updates C-52
ARC
blocking not occurring for signature C-42
device access issues C-39
enabling SSH C-41
inactive state C-37
misconfigured master blocking sensor C-43
verifying device interfaces C-41
automatic updates C-53
cannot access sensor C-24
cidDump C-91
cidLog messages to syslog C-49
communication C-24
corrupted SensorApp configuration C-35
debug logger zone names (table) C-48
debug logging C-44
disaster recovery C-6
duplicate sensor IP addresses C-27
enabling debug logging C-45
external product interfaces 15-10, C-21
gathering information C-68
global correlation 11-12, C-20
IDM
cannot access sensor C-56
will not load C-55
IDSM-2
command and control port C-63
diagnosing problems C-58
not online C-62, C-63
serial cable C-65
status indicator C-60
switch commands C-60
IME time synchronization C-57
IPS modules time drift 4-9, C-16
manual block to bogus host C-41
misconfigured access list C-26
no alerts C-31, C-57
NTP C-50
password recovery 16-9, C-13
physical connectivity issues C-30
preventive maintenance C-2
reset not occurring for a signature C-50
sensing process not running C-28
sensor events C-87
sensor loose connections C-22
sensor not seeing packets C-33
sensor software upgrade C-54
service account 4-18, C-4
show events command C-87
show interfaces command C-85
show statistics command C-75
show tech-support command C-69, C-71
show version command C-72
software upgrades C-52
SPAN port issue C-30
upgrading C-52
verifying Analysis Engine is running C-19
verifying ARC status C-36
Trusted Hosts pane
configuring 12-10
described 12-9
field descriptions 12-9
tuned signatures described 7-4
tuning
AIC signatures 7-39
IP fragment reassembly signatures 7-43
signatures 7-16
turning off anomaly detection 10-35
U
UDLD
configuring 5-22
described 5-22
UDP Protocol tab
described 10-17, 10-23, 10-24, 10-30
enabling UDP 10-17
external zone 10-30
field descriptions 10-30
illegal zone 10-23, 10-24
unassigned VLAN groups described 5-14
unauthenticated NTP 4-7, 4-8, 4-9, 4-15, C-14, C-15
UniDirectional Link Detection see UDLD
UNIX-style directory listings 16-17
Update Sensor pane
configuring 16-21
described 16-20
field descriptions 16-20
user roles 16-20
updating
Cisco.com 16-20
FTP server 16-20
Home pane 1-3
sensors 16-21
upgrade command 21-3, 21-5
upgrading
IPS software 20-8
latest version C-52
maintenance partition
IDSM-2 (Catalyst software) 21-38
IDSM-2 (Cisco IOS software) 21-39
minimum required version 20-8
recovery partition 21-5, 21-11
sensors 21-4
uploading KBs
FTP 17-24
SCP 17-24
Upload Knowledge Base to Sensor dialog box
described 17-24
field descriptions 17-24
URLs for Cisco Security Center 20-11
Users pane
configuring 4-19
field descriptions 4-18
user roles A-29
using
debug logging C-44
TCP reset interfaces 5-7
V
VACLs
described 13-3
Post-Block 13-22
Pre-Block 13-22
verifying
NTP configuration 4-9
password recovery 16-10, C-13
sensor initialization 18-28
sensor setup 18-28
viewing
IP logs 17-15
statistics 17-32
system information 17-32
virtual sensors
adding 3-13, 6-11
default virtual sensor 6-3, 6-8
deleting 6-11
described 6-2, 6-8
editing 6-11
stream segregation 6-4
Virtual Sensors window described 3-12
VLAN groups
802.1q encapsulation 5-14
configuration restrictions 5-9
configuring 5-24
deploying 5-23
described 5-13
switches 5-23
VLAN Groups pane
configuring 5-24
described 5-23
field descriptions 5-24
user roles 5-23
VLAN IDs 5-23
VLAN Pairs pane
configuring 5-21
describing 5-20
field descriptions 5-20
W
watch list rating
calculating risk rating 6-6, 9-4
described 6-6, 9-4
Web Server
described A-3, A-21
HTTP 1.0 and 1.1 support A-21
private keys A-20
public keys A-20
SDEE support A-21
worms
Blaster 10-2
Code Red 10-2
histograms 10-12
Nimbda 10-2
protocols 10-3
Sasser 10-2
scanners 10-3
Slammer 10-2
SQL Slammer 10-2
Z
zones
external 10-4
illegal 10-4
internal 10-4