Chapter 10 Configuring the Sensor Using the CLI
IDSM-2 Configuration Tasks
10-98
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Step 4
Configure an ACL to designate which packets will be captured:
Router(config)# ip access-list extended
word
Step 5
Select the interface that carries the packets to be captured:
Router(config)# interface
interface_name
Step 6
Apply the ACL created in Step 4 to the interface selected in Step 5:
Router(config-if)# mls ip ids
word
Enable the capture function on the IDSM-2 data ports so that packets
with the capture bit set are received by the interface:
Router(config)# intrusion-detection module 4 data-port 1 capture
Router(config)# intrusion-detection module 4 data-port 2 capture
Caution
For the IDSM-2 to capture all packets marked by the mls ip ids command, data
port 1 or data port 2 of the IDSM-2 must be a member of all VLANs to which
those packets are routed.
Miscellaneous Tasks
This section contains procedures such as resetting the IDSM-2 and lists of
Catalyst and Cisco IOS software commands.
Note
For more detailed information on Catalyst and Cisco IOS software commands,
refer to the command references found on Cisco.com. See the Cisco Intrusion
Detection System (IDS) Hardware and Software Version 4.1 Documentation
Guide that shipped with your IDSM-2 for instructions on how to locate these
documents.
This section contains the following topics:
•
Enabling a Full Memory Test, page 10-99
•
Resetting the IDSM-2, page 10-101
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...