When the IPS-enabled rules engine detects a certain number of failed login attempts to or from the same IP address occurring within a rolling 60‑second window, a brute-force attack is suspected. Based on this and other criteria, the rules engine determines whether the suspicious activity constitutes a brute-force event.
The system initializes with a default threshold value for detecting brute-force events. You can configure a higher threshold to reduce false positive IPS events.
Prerequisites
You are logged in to the IPS appliance as an Operator or Admin.
Procedure
Enable the CLI configuration mode.
hostname > enable hostname # configure terminal
Check the current value of the threshold. In the following example, the feature is enabled with default values.
hostname (config) # show ips reconnaissance Ping sweep threshold : 20 Port scan threshold : 200 Brute force threshold : 5Configure a new brute-force threshold value. In the following example, the threshold is raised to 10.
hostname (config) # ips brute-force threshold 10Confirm your changes.
hostname (config) # show ips reconnaissance Ping sweep threshold : 20 Port scan threshold : 200 Brute force threshold : 10Save your changes.
hostname (config) # write memory