Configuring Cisco IOS IPS

上传人:洪易 文档编号:2672072 上传时间:2017-07-26 格式:PPT 页数:33 大小:2.42MB
返回 下载 相关 举报
Configuring Cisco IOS IPS_第1页
第1页 / 共33页
Configuring Cisco IOS IPS_第2页
第2页 / 共33页
Configuring Cisco IOS IPS_第3页
第3页 / 共33页
Configuring Cisco IOS IPS_第4页
第4页 / 共33页
Configuring Cisco IOS IPS_第5页
第5页 / 共33页
点击查看更多>>
资源描述

《Configuring Cisco IOS IPS》由会员分享,可在线阅读,更多相关《Configuring Cisco IOS IPS(33页珍藏版)》请在金锄头文库上搜索。

1、Cisco IOS Threat Defense Features,Configuring Cisco IOS IPS,Configuring Cisco IOS IPS,Cisco IOS IPS Configuration Steps,Configure basic IPS settings:Specify SDF locationConfigure failure parameterCreate an IPS rule and, optionally, combine it with a filterApply the IPS rule to interfaceConfigure enh

2、anced IPS settings:Merge SDFsDisable, delete, and filter selected signaturesReapply the IPS rule to the interfaceVerify the IPS configuration.,Configure Basic IPS Settings,Router# show running-config | begin ips ! Drop all packets until IPS is ready for scanning ip ips fail closed! IPS rule definiti

3、onip ips name SECURIPS list 100!.interface Serial0/0ip address 172.31.235.21 255.255.255.0! Apply the IPS rule to interface in inbound directionip ips SECURIPS in.,Configure Enhanced IPS Settings,! Merge built-in SDF with attack-drop.sdf, and copy to flashRouter# copy flash:attack-drop.sdf ips-sdfRo

4、uter# copy ips-sdf flash:my-signatures.sdfRouter# show runnning-config | begin ips! Specify the IPS SDF locationip ips sdf location flash:my-signatures.sdf ip ips fail-closed! Disable sig 1107, delete sig 5037, filter sig 6190 with ACL 101ip ips signature 1107 0 disableip ips signature 5037 0 delete

5、ip ips signature 6190 0 list 101ip ips name SECURIPS list 100.interface Serial0/0ip address 172.31.235.21 255.255.255.0! Reapply the IPS rule to take effectip ips SECURIPS in.,Verifying IOS IPS Configuration,Router# show ip ips configurationConfigured SDF Locations: flash:my-signatures.sdfBuiltin si

6、gnatures are enabled but not loadedLast successful SDF load time: 13:45:38 UTC Jan 1 2006IPS fail closed is enabled.Total Active Signatures: 183Total Inactive Signatures: 0Signature 6190:0 list 101Signature 1107:0 disableIPS Rule Configuration IPS name SECURIPS acl list 100Interface Configuration In

7、terface Serial0/0 Inbound IPS rule is SECURIPS Outgoing IPS rule is not set,Cisco IOS IPS SDM Tasks,Cisco IOS IPS SDM Tasks,Tasks included in the IPS Policies wizard:Quick interface selection for rule deploymentIdentification of the flow directionDynamic signature updateQuick deployment of default s

8、ignaturesValidation of router resources before signature deploymentSignature customization available in the SDM IPS Edit menu: DisableDeleteModify parameters,Selecting Interfaces and Configuring SDF Locations,Launching the IPS Policies Wizard,Launch the wizard with the default signature parameters,C

9、ustomization options,1.,2.,3.,4.,IPS Policies Wizard Overview,Identifying Interfaces and Flow Direction,Select interface,Identify direction,Selecting SDF Location,Add SDF location,Optionally, use built-in signatures as backup,Selecting SDF Location (Cont.),Select location from flash,Select location

10、from network,Selecting SDF Location (Cont.),Viewing the IPS Policy Summary and Delivering the Configuration to the Router,Viewing the IPS Policies Wizard Summary,Verifying IPS Deployment,1.,2.,3.,4.,Configuring IPS Policies and Global Settings,IPS Policies,Global Settings,Viewing SDEE Messages,Viewi

11、ng All SDEE Messages,Select message type for viewing,Viewing SDEE Status Messages,Status messages report the engine states,Viewing SDEE Alerts,Signatures fire SDEE alerts,Tuning Signatures,Selecting a Signature,Edit signature,Editing a Signature,Click to edit,Select severity,Disabling a Signature Gr

12、oup,Select category,1.,Select All,2.,Disable,3.,4.,Verifying the Tuned Signatures,Summary,You can configure IPS policy on a router by using the CLI or the SDM.CLI does not display the signature parameters.IPS CLI allows you to specify SDF locations, merge SDF files, disable signatures, assign rules

13、to interfaces, and limit the detection scope using ACLs.SDM offers a wizard that simplifies the IPS configuration.IPS Policies wizard deploys default signature definitions from a specified SDF location.You can then use the SDM to edit the policy and modify global settings.SDM offers a view for SDEE

14、messages containing status, errors, and alerts.You can use the SDM to tune the signature parameters.,Module Summary,Cisco IOS Firewall combines the stateful firewall engine with application-layer filtering for selected applications.Cisco IOS Firewall provides stateful support for TCP, UDP, and ICMP.

15、Cisco IOS Firewall can be configured through the CLI, or the SDM, which provides the Basic and Advanced Firewall Configuration wizards for expedited deployment.IDS and IPS are considered complementary technologies that differ in reaction to attack, placement in the network, and signature tuning.Host and network IPS should be deployed in parallel to maximize the protection strength.Cisco IOS IPS can be configured, tuned, and monitored through the CLI or SDM, which offers a wizard for simplified provisioning.,

展开阅读全文
相关资源
相关搜索

当前位置:首页 > 商业/管理/HR > 管理学资料

电脑版 |金锄头文库版权所有
经营许可证:蜀ICP备13022795号 | 川公网安备 51140202000112号