7-3
Installing Cisco Intrusion Prevention System Appliances and Modules 5.0
78-16124-01
Chapter 7 Installing IDSM-2
Using the TCP Reset Interface
Using the TCP Reset Interface
IDSM-2 has a TCP reset interface—port 1. IDSM-2 has a specific TCP reset interface because it cannot
send TCP resets on its sensing ports.
If you have reset problems with IDSM-2, try the following:
•
If the sensing ports are access ports (a single VLAN), you need to configure the reset port to be in
the same VLAN.
•
If the sensing ports are dot1q trunk ports (multi-VLAN), the sensing ports and reset port all must
have the same native VLAN, and the reset port must trunk all the VLANs being trunked by both the
sensing ports.
Front Panel Features
IDSM-2 (
Figure 7-1
) has a status indicator and a Shutdown button.
Figure 7-1
IDSM-2 Front Panel
Table 7-3
describes the IDSM-2 states as indicated by the status indicator.
To prevent corruption of IDSM-2, you must use the shutdown command to shut it down properly. For
instructions on properly shutting down IDSM-2, see Step 1 of
Removing IDSM-2, page 7-10
. If IDSM-2
does not respond, firmly press the Shutdown button on the faceplate and wait for the Status indicator to
turn amber. The shutdown procedure may take several minutes.
Caution
Do not remove IDSM-2 from the switch until the module shuts down completely. Removing the module
without going through a shutdown procedure can corrupt the application partition on the module and
result in data loss.
INTRUSION DETECTION MODULE
SHUTDOWN
WS-SVC-IDSM2
STATUS
83832
Table 7-3
Status Indicator
Color
Description
Green
All diagnostics tests pass—IDSM-2 is operational.
Red
A diagnostics test other than an individual port test failed.
Amber
IDSM-2 is running through its boot and self-test diagnostics sequence, or IDSM-2 is
disabled, or IDSM-2 is in the shutdown state.
Off
IDSM-2 power is off.