User manual
7-50
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter 7 Defining Signatures
Creating Custom Signatures
component-sig-id: 1000
component-subsig-id: 0 default: 0
component-count: 1 default: 1
is-not-component: false <defaulted>
-----------------------------------------------
-----------------------------------------------
NAME: m2
-----------------------------------------------
component-sig-id: 1001
component-subsig-id: 0 <defaulted>
component-count: 1 <defaulted>
is-not-component: true default: false
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
meta-key
-----------------------------------------------
Axxx
-----------------------------------------------
unique-victims: 1 <defaulted>
-----------------------------------------------
-----------------------------------------------
component-list-in-order: false default: false
all-components-required: true default: true
all-nots-required: false default: false
-----------------------------------------------
sensor(config-sig-sig-met)#
Step 14
Exit signature definition submode.
sensor(config-sig-sig-met)# exit
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Step 15
Press Enter to apply the changes or enter
no
to discard them.
For More Information
•
For more information on Signature Event Action Processor, see Signature Event Action Processor,
page 8-3.
•
For more information on the Meta engine, see Meta Engine, page B-33.
Example IPv6 Engine Signature
Caution
A custom signature can affect the performance of your sensor. Test the custom signature against a
baseline sensor performance for your network to determine the overall impact of the signature.