Displays the IPS detection thresholds for reconnaissance activity and brute-force attacks, provided that IPS detection of reconnaissance activity is enabled.
This command is not supported on SmartVision Edition appliances, which are Network Security appliances with SmartVision Edition licenses. The SmartVision Edition sensor is also called Trellix Network Security, SmartVision Edition.
Note
You can also run this command remotely from the command line of an integrated Trellix Central Management System appliance using the central management appliance proxying mechanism.
Syntax
show ips reconnaissance
Parameters
None
Output fields
The following table describes the output fields for the command. Fields are listed in the approximate order in which they appear in the output.
Field Name | Field Description |
|---|---|
IPS reconnaissance is disabled | IPS detection of reconnaissance activity is disabled. No threshold settings are displayed. |
Ping sweep threshold | The appliance triggers an IPS ping sweep event when the number of ICMP exchanges to or from the same IP address within a rolling 60-second window exceeds this value. |
Port scan threshold | The appliance triggers an IPS port scan event when the number of TCP or UDP exchanges to or from the same IP address within a rolling 60-second window exceeds this value. |
Brute force threshold | The appliance triggers an IPS brute-force event when the number of .failed login attempts to or from the same IP address within a rolling 60-second window exceeds this value. |
Example
show ips reconnaissance (Detection Disabled)
hostname # show ips reconnaissance IPS reconnaissance is disabled
show ips reconnaissance (Detection Enabled With Default Settings)
hostname # show ips reconnaissance Ping sweep threshold : 20 Port scan threshold : 200 Brute force threshold : 5
User role
Monitor, Analyst, Operator, or Admin
Command mode
Enable
Supported appliances
This command is supported on the following appliance running the specified release or later:
Network Security: Release 7.5.0