User manual

7-50
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter 7 Defining Signatures
Creating Custom Signatures
component-sig-id: 1000
component-subsig-id: 0 default: 0
component-count: 1 default: 1
is-not-component: false <defaulted>
-----------------------------------------------
-----------------------------------------------
NAME: m2
-----------------------------------------------
component-sig-id: 1001
component-subsig-id: 0 <defaulted>
component-count: 1 <defaulted>
is-not-component: true default: false
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
meta-key
-----------------------------------------------
Axxx
-----------------------------------------------
unique-victims: 1 <defaulted>
-----------------------------------------------
-----------------------------------------------
component-list-in-order: false default: false
all-components-required: true default: true
all-nots-required: false default: false
-----------------------------------------------
sensor(config-sig-sig-met)#
Step 14
Exit signature definition submode.
sensor(config-sig-sig-met)# exit
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Step 15
Press Enter to apply the changes or enter
no
to discard them.
For More Information
For more information on Signature Event Action Processor, see Signature Event Action Processor,
page 8-3.
For more information on the Meta engine, see Meta Engine, page B-33.
Example IPv6 Engine Signature
Caution
A custom signature can affect the performance of your sensor. Test the custom signature against a
baseline sensor performance for your network to determine the overall impact of the signature.