Chapter 1 Introducing the Sensor
Appliances
1-2
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
•
Appliance Restrictions, page 1-9
•
Setting Up a Terminal Server, page 1-9
Introducing the Appliance
The appliance is a high-performance, plug-and-play device. The appliance is a
component of the Intrusion Detection System (IDS), a network-based, real-time
intrusion detection system. See
Supported Sensors, page 1-16
, for a list of
supported appliances.
You can use the Command Line Interface (CLI), IDS Device Manager, or
Management Center for IDS Sensors to configure the appliance. Refer to your
IDS manager documentation. To access IDS documentation on Cisco.com, refer
to Cisco Intrusion Detection System (IDS) Hardware and Software Version 4.1
Documentation Guide that shipped with your appliance.
You can configure the appliance to respond to recognized signatures as it captures
and analyzes network traffic. These responses include logging the event,
forwarding the event to the IDS manager, performing a TCP reset, generating an
IP log, capturing the alert trigger packet, and/or reconfiguring a router.
After being installed at key points in the network, the appliance monitors and
performs real-time analysis of network traffic by looking for anomalies and
misuse based on an extensive, embedded signature library. When the system
detects unauthorized activity, appliances can terminate the specific connection,
permanently block the attacking host, log the incident, and send an alert to the IDS
manager. Other legitimate connections continue to operate independently without
interruption.
Appliances can also monitor and analyze syslog messages from Cisco routers to
detect and report network security policy violations.
Appliances are optimized for specific data rates and are packaged in Ethernet,
Fast Ethernet, and Gigabit Ethernet configurations. In switched environments,
appliances must be connected to the switch’s Switched Port Analyzer (SPAN) port
or VLAN Access Control list (VACL) capture port.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...