8-4
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
OL-18504-01
Chapter 8 Installing the NME IPS
Hardware Interfaces
•
The Cisco access routers only support one IDS/IPS per router.
•
When you reload the router, the NME IPS also reloads. To ensure that there is no loss of data on the
NME IPS, make sure you shut down the module using the
shutdown
command before you use the
reload
command to reboot the router.
For More Information
•
For more information on how the NME IPS functions with other IPS modules, see
Interoperability
With Other IPS Modules, page 8-3
.
•
For more information about shutting down the NME IPS, refer to
Rebooting, Resetting, and
Shutting Down the NME IPS
.
Hardware Interfaces
Figure 8-1
shows the router and the NME IPS interfaces used for internal and external communication.
You can configure the router interfaces through the Cisco IOS CLI and the NME IPS interfaces through
the IPS CLI, IDM, IME, or CSM.
Figure 8-1
NME IPS and Router Interfaces
1
Router interface to external link
Configure the standard router settings using the Cisco IOS CLI.
2
Router interface to the NME IPS (ids-sensor x/0)
Configure the IP address and default gateway router of the NME IPS using the Cisco IOS CLI.
3
The NME IPS interface to router (GigabitEthernet0/1)
Configure the interface as inline or promiscuous using the Cisco IOS CLI.
4
The NME IPS interface to external link (Management0/1)
Configure the command and control interface using the IPS CLI, IDM, IME, or CSM.
204574
Router interface to module
Host Router (Top View)
Module interface to router
Network Module
Module interface to external link
Router interface to external link
1
4
3
2