Cisco Cisco Firepower Management Center 4000

다운로드
페이지 1844
 
25-45
FireSIGHT System User Guide
 
Chapter 25      Using Application Layer Preprocessors
  Using the Sun RPC Preprocessor
Note
Any port you add to the RPC 
Ports
 list should also be added in each TCP policy to the 
appropriate list of TCP reassembly ports, depending on whether you are monitoring client 
or server traffic, or both. Note, however, that reassembling additional traffic types (client, 
server, both) increases resource demands. For more information on configuring TCP 
reassembly ports, see 
.
Detect fragmented RPC records
Detects RPC fragmented records.
You can enable rules 106:1 and 106:5 to generate events for this option. See 
 for more information.
Detect multiple records in one packet
Detects more than one RPC request per packet (or reassembled packet).
You can enable rule 106:2 to generate events for this option. See 
 for 
more information.
Detect fragmented record sums which exceed one fragment
Detects reassembled fragment record lengths that exceed the current packet length.
You can enable rule 106:3 to generate events for this option. See 
 for 
more information.
Detect single fragment records which exceed the size of one packet
Detects partial records.
You can enable rule 106:4 to generate events for this option. See 
 for 
more information.
Configuring the Sun RPC Preprocessor
License: 
Protection
You can use the following procedure to configure the Sun RPC preprocessor. For more information on 
the Sun RPC preprocessor configuration options, see 
To configure the Sun RPC preprocessor:
Access: 
Admin/Intrusion Admin
Step 1
Select 
Policies > Intrusion > Intrusion Policy
.
The Intrusion Policy page appears.
Step 2
Click the edit icon (
) next to the policy you want to edit.
If you have unsaved changes in another policy, click 
OK
 to discard those changes and continue. See 
 for information on saving unsaved changes in another 
policy.
The Policy Information page appears.
Step 3
Click 
Advanced Settings
 in the navigation panel on the left.