Intrusion Detection/Intrusion Prevention System
Left running head:
Chapter name (automatic)
924
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
Alcatel-Lucent
IDS/IPS CONFIGURATION COMMANDS
The following commands are used to configure IDS/IPS on the OmniAccess 5740
USG.
T
O CONFIGURE AN IDS/IPS SENSOR
Note: The OmniAccess 5740 USG supports Snort based sensors.
E
XAMPLE
ALU(config)#firewall
ALU(config-firewall)# intrusion sensor sensor1 snort threshold
10 1000
ALU(config-firewall-intrusion-sensor-sensor1)#
ALU(config-firewall)# intrusion sensor sensor1 snort no
threshold
ALU(config-firewall)# no intrusion sensor sensor1 snort
Command (in FwCM) Description
intrusion sensor <name> snort
[no threshold|threshold <1-
4294967295> <1-4294967295>]}
Use this command to create an
intrusion sensor based on snort. Enter
this command in the Firewall
configuration mode.
Use the ‘threshold’ keyword to
configure the threshold for the sensor.
Use the ‘no threshold’ keyword to
remove threshold configured for the
sensor.
no intrusion sensor <name>
snort
Use this command to delete an
intrusion sensor.
Note: You cannot delete the
intrusion sensor if it is
attached to a firewall policy.
Detach the sensor from the
firewall policy before
deleting it.