10-61
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
Allowing the Sensor to Block Itself
Caution
We recommend that you do not permit the sensor to block itself, because it may
stop communicating with the blocking device. You can configure this option if
you can ensure that if the sensor creates a rule to block its own IP address, it will
not prevent the sensor from accessing the blocking device.
To allow the sensor to block itself, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Enter network access mode:
sensor(config)# service networkAccess
Step 4
Enter general submode:
sensor(config-NetworkAccess)# general
Step 5
Configure the sensor to block itself:
sensor(config-NetworkAccess-gen)# allow-sensor-shun true
By default, this value is false.
Step 6
Exit general submode:
sensor(config-NetworkAccess-gen)# exit
sensor(config-NetworkAccess)# exit
Apply Changes:?[yes]:
Step 7
Type yes to apply changes.
Note
To reverse this procedure, follow the steps but change the value in Step 5
from true to false.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...