10-57
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
Configuring Blocking
This section describes how to set up blocking using the CLI.
This section contains the following topics:
•
Understanding Blocking, page 10-57
•
Before Configuring Blocking, page 10-59
•
Supported Blocking Devices, page 10-59
•
Configuring Blocking Properties, page 10-60
•
Configuring Addresses Never to Block, page 10-65
•
Configuring Logical Devices, page 10-66
•
Configuring Blocking Devices, page 10-67
•
Configuring the Sensor to be a Master Blocking Sensor, page 10-73
•
Obtaining a List of Blocked Hosts and Connections, page 10-75
•
How to Set up Manual Blocking and How to Unblock, page 10-76
Understanding Blocking
NAC, the blocking application on the sensor, starts and stops blocks on routers,
switches, and PIX firewalls. NAC blocks the IP address on the devices it is
managing. It sends the same block to all the devices it is managing, including any
other master blocking sensors. NAC monitors the time for the block and removes
the block after the time has expired.
For a more detailed discussion of blocking, see
NAC, page A-16
.
There are two types of blocks:
•
Host block—Blocks all traffic from a given IP address
•
Connection block—Blocks traffic from a given source IP address to a given
destination IP address and destination port
Note
Multiple connection blocks from the same source IP address to either a different
destination IP address or destination port automatically switch the block from a
connection block to a host block.
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...