Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-62
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Disabling Blocking
By default, blocking is enabled on the sensor. If NAC is managing a device and
you need to manually configure something on that device, you should disable
blocking first. You want to avoid a situation in which both you and NAC could be
making a change at the same time on the same device. This could cause the device
and/or NAC to crash.
To disable blocking, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Enter network access mode:
sensor(config)# service networkAccess
Step 4
Enter general submode:
sensor(config-NetworkAccess)# general
Step 5
Disable blocking on the sensor:
sensor(config-NetworkAccess-gen)# shun-enable false
By default, this value is true.
Step 6
Exit general submode:
sensor(config-NetworkAccess-gen)# exit
sensor(config-NetworkAccess)# exit
Apply Changes:?[yes]:
Step 7
Type yes to apply changes.
Note
To enable blocking, follow the steps but change the value in Step 5 from
false to true.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...