10-71
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
Note
If you are using DES or 3DES, you must use the command ssh host-key
ip_address to accept the key or NAC cannot connect to the device.
Step 6
Specify the sensor’s NAT address:
sensor(config-NetworkAccess-cat)# nat-address
nat_address
Note
This changes the IP address in the first line of the ACL from the sensor’s
address to the NAT address.
Step 7
Specify the VLAN number:
sensor(config-NetworkAccess-cat)# shun-interfaces vlan
vlan_number
Step 8
Add the preShun ACL name (optional):
sensor(config-NetworkAccess-cat-shu)# pre-acl-name
pre_shun_acl_name
Step 9
Add the postShun ACL name (optional):
sensor(config-NetworkAccess-cat-shu)# post-acl-name
post_shun_acl_name
Step 10
Exit shun device configuration submode:
sensor(config-NetworkAccess-cat-shu)# exit
sensor(config-NetworkAccess-cat)# exit
sensor(config-NetworkAccess)# exit
sensor(config)# exit
Apply Changes:?[yes]:
Note
You receive an error if the logical device name does not exist.
Step 11
Type yes to apply changes.
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...