Appendix A Intrusion Detection System Architecture
System Components
A-18
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Figure A-2
NAC Application
Note
A NAC application instance can control 0, 1, or many network devices. NAC does
not share control of any network device with other NAC applications, IDS
management software, other network management software, or system
administrators. Only one NAC application instance is allowed to run on a given
sensor.
NAC initiates a block in response to one of the following:
•
An alert event generated from a signature that is configured with a block
action
•
A block configured manually through the CLI, IDM, or the IDS MC
•
A block configured permanently against a host or network address
119097
IDAPI
NAC
Sensor
Block
Subscription
Block Event
EventStore
Block CT
Block CT
Response
Block
Subscription
Block Event
Block CT
Block CT
Response
CT Source
Routers-PIX Firewalls
IDAPI
NAC
Master Blocking Sensor
Block CT
Block CT
Response
Block CT
Block CT
Response
Routers-PIX Firewalls
CT Server
Web Server
Block CT
Block CT
Response
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...