IPS detection of reconnaissance activity is disabled by default. If you enable this feature, the platform triggers IPS events when reconnaissance activity is detected.
Note
Reconnaissance detection consumes additional system resources. Depending on your traffic load and IPS policies, operating the platform in reconnaissance detection mode can slow IPS processing.
The platform uses default threshold values for ping sweep detection and port scan detection. You can configure higher detection thresholds to reduce false positive IPS events. See Configuring the detection thresholds for reconnaissance events (CLI).
Prerequisites
Log in to the CLI of the IPS appliance as Operator or Admin.
Procedure
Enable the CLI configuration mode.
hostname > enable hostname # configure terminal
Check the current status of the feature. In the following example, the feature is not yet enabled.
hostname (config) # show ips reconnaissance IPS reconnaissance is disabledEnable or disable the feature. In the following example, the command enables the feature.
hostname (config) # ips reconnaissance enableConfirm your changes. The following example displays the default settings.
hostname (config) # show ips reconnaissance Ping sweep threshold : 20 Port scan threshold : 200 Brute force threshold : 5Save your changes.
hostname (config) # write memory