Technical Documentation

Configuring IDS Rule Sets

The rule-set statement defines a collection of IDS rules that determine what actions the router software performs on packets in the data stream. You define each rule by specifying a rule name and configuring terms. Then, you specify the order of the rules by including the rule-set statement at the [edit services ids] hierarchy level with a rule statement for each rule:

[edit services ids]rule-set rule-set-name {rule rule-name;}

The router software processes the rules in the order in which you specify them in the configuration. If a term in a rule matches the packet, the router performs the corresponding action and the rule processing stops. If no term in a rule matches the packet, processing continues to the next rule in the rule set. If none of the rules matches the packet, the packet is dropped by default.

Related Topics


Published: 2010-07-19

Help
|
My Account
|
Log Out