A sensor template is a configuration that defines protocol Deep Packet Inspection (DPI) engines and UDP/TCP port mappings for a Cisco Cyber Vision sensor.
You can create and configure sensor templates, then assign them to specific sensors.
Protocol DPI engines
Enable or disable a protocol DPI engine to select which protocols to analyze.
Disable a protocol DPI engine to avoid false positives in Cisco Cyber Vision. A false positive occurs when a protocol appears in the user interface but is not present because other non-standardized protocols can use the same UDP/TCP ports.
Default template
The Default template disables some protocols because they are not commonly used or are specific to fields such as transportation.
The Default template applies to all compatible sensors.
UDP and TCP port mappings
Although UDP/TCP port configurations are mostly standardized, conflicts can occur for field-specific protocols or protocols with limited use. Map UDP/TCP port numbers to send packets to the correct DPI engine for accurate analysis and representation in the user interface.
Sending a protocol packet to the wrong port causes related information to appear in Security Insights/Flows without a tag.
Template assignment and deployment
A sensor can be associated with only one template.
Template deployment fails in the following situations:
-
The sensor is disconnected.
-
The sensor has connection issues.
-
The sensor version is too old.