Cisco IPS Sensor Tuning Timesavers
Over the years I’ve gathered lots of configuration tips for Cisco Security gear. Some I’ve learned through blood, sweat and tears and some were passed along to me from others who acquired them the same way. I figure its high time I pass some on to you as well. Each week I’ll post a blog of another Cisco Security configuration tip, if there are certain products you’d like tips on just let me know by commenting on this blog. This week I’ve picked Cisco IPS.
Like all IPS products out there Cisco’s IPS needs to be tuned for your environment if you want it to be most effective. By default, Cisco IPS comes with a subset of it signature base enabled and a subnet of it disabled. It also comes out of the box set to drop on certain signatures and Risk Ratings. Check out my previous article on the topic for details. Even though the sensor comes with some a pre-tuned signature set it is still necessary to tailor the sensor to your particular environment. Tuning for me means two things: tuning out the false positives found in your environment and also enabling some default disabled signatures to increase the sensors effectiveness in your environment. Both jobs can be time consuming if you haven’t worked with the solution before so here are some tips to help you tune your sensors quicker.
1) Create a new Min-Risk (minimum risk) risk category in event action rules. First change the risk threshold to 30 on the built-in LOWRISK category. Then add in your new Min-Risk category with a risk threshold of 1.

2) Create an Event Action override to stop alerting on any signature hit with a risk rating of less than 30. It is rare that a signature hit whose risk rating value stays below 30 is real or worth your attention. Therefore tuning out any RR hit less than 30 maintains your security and cuts down on frivolous event data.

3) Define your mission critical hosts under the target value rating configuration section. The target value rating (TVR) is used to adjust your risk rating higher or lower. The more critical a host is the greater the risk rating will be changed. Server farms and data center subnets are good candidates to define as mission critical.
You also want to tell your IPS what hosts have a low criticality. Typically, guest networks should be put into this category. The more information you provide the sensor about your network using the various TVR settings the better it will protect your network and provide you with meaningful event data.

4) While you are going through your tuning stage and your IPS is inline I recommend that you turn off the default Event Action Override. The default rule will drop any traffic that has a risk rating of 90-100. Disabling this rule stops the sensor from dropping traffic based on risk rating.

Some signatures are set to drop packets by default. To quickly override the drop functions of these signatures while you are tuning your sensor, create an event action filter. This filter rule will remove all drop functions from signatures. The two tasks in tip number 4 will ensure that your IPS sensor does not drop any traffic until you want it to. It gives you peace of mind that you’ll not drop any critical traffic while you are still in the middle of tuning the sensor for the environment.

5) Turn on IPS Global Correlation with “standard” risk rating adjustment enabled. Also enable reputation filtering. This is a small list of know very bad IP addresses that if seen by your sensor will get dropped outright. Using these features will drastically increase the efficacy of your drop decisions. Note: this feature only works if the sensor will see source addresses from the Internet. If it is purely internal traffic than you will see little value from this feature.

If you have any tuning tips of your own please post them for all to learn from. Here is a Cisco IPS Tuning guide that has some good tips in it as well. The guide is a little dated but still uses sound best practices for tuning. http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/overview_c17-464691.html Happy tuning!
The opinions and information presented here are my PERSONAL views and not those of my employer. I am in no way an official spokesperson for my employer.
More from Jamey Heary: Credit Card Skimming: How thieves can steal your card info without you knowing it Google Nexus One vs. Top 10 Phone Security RequirementsWhy you should always shred your boarding pass Video rental records are afforded more privacy protections than your online dataThe truth about new SSL attacks 2009 Top Urban Legends in IT Security/a>Go to Jamey’s Blog for more articles on security.*
*
*
*
*
*




