Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-60
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
•
Catalyst 6000 switches with Catalyst software version 7.5(1) or later
(VACLs)
–
Sup1A
–
Sup1A/PFC
–
Sup1A/MSFC1
–
Sup1A/MFSC2
–
Sup2/MSFC2 required
•
PIX Firewall with version 6.0 or later (shun command)
–
501
–
506E
–
515E
–
525
–
535 required
You configure blocking using either ACLs, VACLS, or the shun command. All
PIX Firewall models support the shun command.
Configuring Blocking Properties
You can change the default blocking properties through the CLI. It is best to use
the default properties, but if you need to change them, use these procedures.
This section contains the following topics:
•
Allowing the Sensor to Block Itself, page 10-61
•
Disabling Blocking, page 10-62
•
Setting Maximum Block Entries, page 10-63
•
Setting the Block Time, page 10-64
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...