Use the Advanced Device Settings page to configure settings for packet captures, tunneled traffic, and CLI activity.
At an Admin domain level, select Devices → <Admin Domain Name> → Global → IPS Device Settings → Advanced Device Settings.
The Advanced Device Settings page appears.
Note
Alternatively, you can configure these settings for a Sensor from Devices → <Admin Domain Name> → Devices → <Sensor_name> → Setup → Advanced → Advanced Device Settings.
The bytes to be captured when pre-attack capturing is enabled is set in the IPS Policy and is displayed on this page. Valid values are 128 and 256 bytes.
Select the Inspect Tunneled traffic checkbox to parse IPv4 and IPv6 traffic for all supported tunneling protocols like GRE, GTP for malware detection. By default, this checkbox is deselected.
Select a Snort Rule Engine. You can select either the Trellix IPS Snort engine or the Suricata Snort engine. By default, the Snort Rule Engine is set to Trellix IPS Snort.
Note
The Suricata Snort engine is not available on NS9600, NS7600 and NS3600 Sensors.
From CLI Activity Logging options, select Log to Device Only, Log to Manager Only, or Log to Device and Manager to track executed CLI commands. By default, this is set to Disabled.
.png)
Select Show CPU usage in the CLI to determine the Sensor load. By default, this checkbox is deselected.
Select Log SSH Access to the CLI to log all attempts to access CLI on the device. By default, this checkbox is deselected.
Use the Restrict SSH Access to CLI checkbox to configure IP addresses or CIDR blocks to restrict SSH access. You can set IPv4 and IPv6 blocks and click Add. By default, this checkbox is deselected.
Note
For Virtual IPS Sensors in the AWS environment, this checkbox must be selected and the IPv4/IPv6 CIDR blocks must be added to restrict SSH access from external invalid IPs.
.png)
Click Save.