12-26-2012 05:32 AM - edited 03-10-2019 05:51 AM
Hi,
I have IPS 4270, is there signature for port scanning, so that it fires when any user run the scan (angry port scan, etc.....), if not can i creat a signature for this, how ???
thankssss
12-26-2012 11:13 AM
I think the sweep engine and signatures related to it are responsible for what you want to achieve.
"How???"
Have you tried to read cisco guide on how to configure IPS and how it works? I think it's the best way to find out.
12-26-2012 05:17 PM
Hello Alkabeer,
Ofcourse there are Check the Dos categories.
You could also use the anomaly detection feature that will allow you to set a base-line in your network to determine what is normal and what is not.
Regards,
Jcarvaja
01-02-2013 11:11 AM
I believe there is a whole category called "reconnaisance" devoted to things like that. You should be able to go in and verify that the signature that matches the type of scan you're looking for is enabled and, if not, enable it. If it doesn't exist you can probably copy an existing rule and tweak it for your needs with minimal effort.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide