From the Central Management System appliance CLI, you can use a central management console (CMC) profile to configure a custom IPS policy on managed IPS-enabled platforms in the centralized management domain. You can configure the custom IPS policy on a single managed IPS-enabled platform, or you can configure the policy on a group of managed platforms.
Prerequisites
Log in to the CLI of the Central Management System appliance as Operator or Admin.
Procedure
Enable the CLI configuration mode.
hostname > enable hostname # configure terminal
Configure the first command of the CMC profile to create a custom IPS policy.
The following example configures profile
c1to create a custom IPS policy named p1.hostname (config) # cmc profile c1 comment "IPS policy for IPS-ena NX platforms" hostname (config) # cmc profile c1 command 1 "ips policy p1"
Configure the profile to specify required match attributes for the custom IPS policy.
The following example configures the attributeds
attack‑target,min‑severity, andmax‑severity.hostname (config) # cmc profile c1 command 2 "ips policy p1 match attack-target client" hostname (config) # cmc profile c1 command 3 "ips policy p1 match min-severity 8" hostname (config) # cmc profile c1 command 4 "ips policy p1 match max-severity 10"
(Optional) Configure the profile to specify optional match attributes for the custom IPS policy.
The following example configures an optional
protocolattribute.hostname (config) # cmc profile c1 command 5 "ips policy p1 match protocol SNMP"(Optional) Configure the profile to specify optional rule exclusion or inclusion attributes for the custom IPS policy.
The following example configures the optional attributes
rules excludeandrules include.hostname (config) # cmc profile c1 command 6 "ips policy p1 rules exclude 85300001"hostname (config) # cmc profile c1 command 7 "ips policy p1 rules include 85300002"hostname (config) # cmc profile c1 command 8 "ips policy p1 rules include 85300003"Before you save the CMC profile to managed IPS-enabled platforms, list the CLI commands and comments in the profile.
The following example step lists the CLI commands in the profile
c1.hostname (config) # show cmc profile c1 Profile c1 Comment: IPS policy for IPS-ena NX platforms Commands: 1. ips policy p1 2. ips policy p1 match attack-target client 3. ips policy p1 match min-severity 8 4. ips policy p1 match max-severity 10 5. ips policy p1 match protocol SNMP 6. ips policy p1 rules exclude 85300001 7. ips policy p1 rules include 85300002 8. ips policy p1 rules include 85300003Note
To delete a command from the profile, use the no cmc profile name command and specify the command sequence_number option.
The following example deletes the eighth command from the profile:
hostname (config) # no cmc profile c1 command 8Apply the profile to a single managed IPS-enabled platform or to a group of appliances.
To apply the profile to a single managed appliance, use the cmc profile
name
command and specify the apply appliance
name
option.
The following example step applies the profile to the appliance NX_4400_IPS.
hostname (config) # cmc profile c1 apply appliance NX_4400_IPS ============ Appliance NX_4400_IPS ============ Execution was successful. Execution output: Saving configuration file ... Done!The configuration for the managed appliance NX_4400_IPS includes the definition of the custom IPS profile p1.
To apply the profile to a group of managed appliances, use the cmc profile
name
command and specify the apply group
name
option.
The following example step applies the profile to the appliances in the group NXips, which is composed of IPS-enabled appliances named NX_900_IPS and NX_10000_IPS.
hostname (config) # cmc profile c1 apply group NXips ============ Appliance NX_900_IPS ============ Execution was successful. Execution output: Saving configuration file ... Done! ============ Appliance NX_10000_IPS ============ Execution was successful. Execution output: Saving configuration file ... Done!The configurations for the managed appliances in group NXips include the definition of the custom IPS profile p1.
Save your changes.
hostname (config) # write memory