B-7
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix B Troubleshooting
Troubleshooting the 4200 Series Appliance
Note
If the output says
command-control is down
, there is a hardware issue or
an IP address conflict.
Step 5
SSH fails to connect or the connection is refused:
a.
Make sure the sensor’s access list is configured to accept your IP address.
sensor# show configuration | include accessList
accessList ipAddress 10.0.0.0 netmask 255.0.0.0
accessList ipAddress 10.89.0.0 netmask 255.255.0.0
accessList ipAddress 64.101.0.0 netmask 255.255.0.0
accessList ipAddress 10.89.149.31 netmask 255.255.255.255
accessList ipAddress 64.102.0.0 netmask 255.255.0.0
b.
If the sensor’s access list is correct, make sure the sensor’s SSH and/or Telnet
and web server ports are open in the firewall.
sensor# configure terminal
sensor(config)# service WebServer
sensor(config-WebServer)# show settings
general
-----------------------------------------------
enable-tls: true <defaulted>
ports: 443 <defaulted>
server-id: HTTP/1.1 compliant <defaulted>
-----------------------------------------------
Step 6
Verify that the network cabling for the appliances is correct and operational, and
that the routers and switches are operational for the modules.
IDM Cannot Access the Sensor
If the IDM cannot access the sensor, follow these steps:
Step 1
If you can access the sensor through SSH, verify that you are accessing the correct
port on the sensor and that you are making the correct HTTP versus HTTPs
selection.
You are correctly addressing the sensor.
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...