
10-21
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
78-16527-01
Chapter 10 Configuring Blocking
Configuring Blocking Devices
Note
This changes the IP address in the first line of the ACL from the sensor’s address to the NAT
address. This is not a NAT address configured on the device being managed. It is the address the
sensor is translated to by an intermediate device, one that is between the sensor and the device
being managed.
Step 7
Set the interface name and direction:
sensor(config-net-rou)#
block-interfaces
interface_name
[in | out]
Caution
The name of the interface must either be the complete name of the interface or an abbreviation that the
router recognizes with the
interface
command.
Step 8
(Optional) Add the pre-ACL name:
sensor(config-net-rou-blo)#
pre-acl-name
pre_acl_name
Step 9
(Optional) Add the post-ACL name:
sensor(config-net-rou-blo)#
post-acl-name
post_acl_name
Step 10
Exit network access submode:
sensor(config-net-rou-blo)#
exit
sensor(config-net-rou)#
exit
sensor(config-net)#
exit
sensor(config)#
exit
Apply Changes:?[yes]:
Step 11
Press
Enter
to apply the changes or type
no
to discard them.
Configuring the Sensor to Manage Catalyst 6500 Series Switches and Cisco
7600 Series Routers
This section describes how to configure the sensor to manage Cisco switches. It contains the following
topics:
•
Switches and VACLs, page 10-21
•
Configuring the Sensor to Manage Catalyst 6500 Series Switches and Cisco 7600 Series Routers,
page 10-22
Switches and VACLs
You can configure Network Access Controller to block using VACLs on the switch itself when running
Cisco Catalyst software, or to block using router ACLs on the MSFC or on the switch itself when running
Cisco IOS software. This section describes blocking using VACLs. For blocking using the router ACLS
see
Configuring the Sensor to Manage Cisco Routers, page 10-19
.
You must configure the blocking interfaces on the Catalyst 6500 series switch and specify the VLAN of
traffic you want blocked.