<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Signature Engine in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514620#M66214</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are multiple possible signature engines available, they are discussed here in the user guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_signature_engines.html"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_signature_engines.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The default block timeout on a sensor is 30 minutes, and can be adjusted as your environment needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can view blocked hosts in the IDM GUI by navigating to Monitoring&amp;gt;Time-Based Actions&amp;gt;Host Blocks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; From the CLI it will be the last section of output from:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;show statistics network-access&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Nov 2010 17:08:54 GMT</pubDate>
    <dc:creator>Scott Fringer</dc:creator>
    <dc:date>2010-11-05T17:08:54Z</dc:date>
    <item>
      <title>IPS Signature Engine</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514619#M66210</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While Checking IPS signature database, i noticed that there is a column named engine.&lt;/P&gt;&lt;P&gt;Some signatures are Atomic IP, others Normalizer, i don't know if there is a third value.&lt;/P&gt;&lt;P&gt;but what do that values means?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more question, if a signature Action is set to "block attacker inline" it do block the attacker address IP for a one hour right?&lt;/P&gt;&lt;P&gt;Also is there a way to know from IPS what are the group of IP's blocked for one hour and when??&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514619#M66210</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2019-03-10T12:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Signature Engine</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514620#M66214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are multiple possible signature engines available, they are discussed here in the user guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_signature_engines.html"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_signature_engines.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The default block timeout on a sensor is 30 minutes, and can be adjusted as your environment needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can view blocked hosts in the IDM GUI by navigating to Monitoring&amp;gt;Time-Based Actions&amp;gt;Host Blocks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; From the CLI it will be the last section of output from:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;show statistics network-access&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 17:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514620#M66214</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-11-05T17:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Signature Engine</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514621#M66223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello scott,&lt;/P&gt;&lt;P&gt;i was out of the office for a while, so i couldn't answer before.&lt;/P&gt;&lt;P&gt;thank you very much for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the output of the command is the following:&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;show statistics network-access &lt;BR /&gt;Current Configuration&lt;BR /&gt;&amp;nbsp;&amp;nbsp; LogAllBlockEventsAndSensors = true&lt;BR /&gt;&amp;nbsp;&amp;nbsp; EnableNvramWrite = false&lt;BR /&gt;&amp;nbsp;&amp;nbsp; EnableAclLogging = false&lt;BR /&gt;&amp;nbsp;&amp;nbsp; AllowSensorBlock = false&lt;BR /&gt;&amp;nbsp;&amp;nbsp; BlockMaxEntries = 250&lt;BR /&gt;&amp;nbsp;&amp;nbsp; MaxDeviceInterfaces = 250&lt;BR /&gt;State&lt;BR /&gt;&amp;nbsp;&amp;nbsp; BlockEnable = true&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the "block enable=true" but the other parameter "AllowSensorBlock= false" is that a problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the "AllowSensorBlock= false" is talking about the deny through a firewall or a router right? and not the deny through the IPS itself ONLY!?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shall the IPS itself (and alone without the contribution of a router or firewall) still able to block the ip of a certain host for 30 minutes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, how to adjust the period from 30 minutes to one hour for example!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;al last, once an iIP is blocked how much the IP still appears in the GUI or CMD (show statistics network-access)?&lt;/P&gt;&lt;P&gt;can i view a history of the list of blocked addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Dec 2010 08:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514621#M66223</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2010-12-04T08:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Signature Engine</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514622#M66225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First, let me clarify the differences between &lt;STRONG&gt;blocking&lt;/STRONG&gt; actions and &lt;STRONG&gt;deny &lt;/STRONG&gt;actions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;block &lt;/STRONG&gt;- relies on an external device, such as a firewall or router, to implement the action via a shun or ACL entry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;deny &lt;/STRONG&gt;- performs the action directly on the IPS sensor, requires the sensor to be configured for inline operation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; All of the output provided in the output of the 'show statistics network-access' relates to &lt;STRONG&gt;block&lt;/STRONG&gt; actions. 'AllowSensorBlock' is a parameter that allows the IPS sensor to add its management IP address to a requested block action; this is not usually recommended.&amp;nbsp; To adjust the timeout for blocks to remain active you would make use of the 'global-block-timeout' command from the CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;sensor# &lt;SPAN class="cExBold"&gt;configure terminal&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1135534"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;sensor(config)# &lt;STRONG class="cBold"&gt;service event-action-rules rules0
&lt;/STRONG&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1135535"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;sensor(config-rul)# &lt;/PRE&gt;&lt;/DIV&gt;&lt;DIV class="pPreformatted"&gt;&lt;PRE class="pPreformatted"&gt;sensor(config-rul)# &lt;STRONG class="cBold"&gt;general&lt;/STRONG&gt;&lt;A name="wp1135536"&gt;&lt;/A&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;DIV class="pPreformatted"&gt;&lt;PRE class="pPreformatted"&gt;sensor(config-rul-gen)# &lt;STRONG class="cBold"&gt;global-block-timeout 30&lt;/STRONG&gt;&lt;A name="wp1135539"&gt;&lt;/A&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; The timeout is specified in minutes.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; For deny actions you can adjust the timeout using the 'global-deny-timeout command:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;sensor# &lt;SPAN class="cExBold"&gt;configure terminal&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1135534"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;sensor(config)# &lt;STRONG class="cBold"&gt;service event-action-rules rules0
&lt;/STRONG&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1135535"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;sensor(config-rul)# &lt;/PRE&gt;&lt;/DIV&gt;&lt;DIV class="pPreformatted"&gt;&lt;PRE class="pPreformatted"&gt;sensor(config-rul)# &lt;STRONG class="cBold"&gt;general&lt;/STRONG&gt;&lt;A name="wp1135536"&gt;&lt;/A&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;DIV class="pPreformatted"&gt;&lt;PRE class="pPreformatted"&gt;sensor(config-rul-gen)# &lt;STRONG class="cBold"&gt;global-deny-timeout 1800&lt;/STRONG&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; The timeout is specified in seconds.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; To adjust timeouts using the IDM GUI, please reference this documentation link:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/idm/idm_event_action_rules.html#wp2039284"&gt;http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/idm/idm_event_action_rules.html#wp2039284&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; You can monitor active blocks from the CLI using the 'show statistics network-access' command.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; You can monitor active denies from the CLI using the 'show statistics denied-attackers' command.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; To monitor blocks and denies using the IDM GUI, please reference this documentation link:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/idm/idm_monitoring.html"&gt;http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/idm/idm_monitoring.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; There is not a direct method within the sensor to view historical block/deny lists.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Scott&lt;/DIV&gt;&lt;DIV class="pPreformatted"&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Dec 2010 12:55:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514622#M66225</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-12-06T12:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Signature Engine</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514623#M66232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Dec 2010 12:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-engine/m-p/1514623#M66232</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2010-12-13T12:29:05Z</dc:date>
    </item>
  </channel>
</rss>

