C-17
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
78-16527-01
Appendix C Troubleshooting
Troubleshooting the 4200 Series Appliance
Verifying Network Access Controller Connections are Active
If the State is not
Active
in the Network Access Controller statistics, there is a problem.
To verify that the State is Active in the statistics, follow these steps:
Step 1
Log in to the CLI.
Step 2
Verify that Network Access Controller is connecting:
Check the State section of the output to verify that all devices are connecting.
sensor#
show statistics network-access
Current Configuration
LogAllBlockEventsAndSensors = true
EnableNvramWrite = false
EnableAclLogging = false
AllowSensorBlock = false
BlockMaxEntries = 250
MaxDeviceInterfaces = 250
NetDevice
Type = Cisco
IP = 10.89.147.54
NATAddr = 0.0.0.0
Communications = telnet
BlockInterface
InterfaceName = fa0/0
InterfaceDirection = in
State
BlockEnable = true
NetDevice
IP = 10.89.147.54
AclSupport = uses Named ACLs
Version = 12.2
State = Active
sensor#
Step 3
If Network Access Controller is not connecting, look for recurring errors:
sensor#
show events error
hh:mm:ss month day year
| include : nac
Example:
sensor#
show events error 00:00:00 Apr 01 2005 | include : nac
Step 4
Make sure you have the latest software updates:
sensor#
show version
Upgrade History:
IDS-K9-maj-5.0-1- 14:16:00 UTC Thu Mar 04 2004
Recovery Partition Version 1.1 - 5.0(1)S149
If you do not have the latest software updates, download them from Cisco.com. For the procedure, see
Obtaining Cisco IPS Software, page 18-1
.
Step 5
Read the Readme that accompanies the software upgrade for any known DDTS for Network Access
Controller.
Step 6
Make sure the configuration settings for each device are correct (the username, password, and IP
address).
For the procedure, see
Device Access Issues, page C-18
.