Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-66
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Step 5
Define the address that should never be blocked:
•
For a single host:
sensor(config-NetworkAccess-gen)# never-shun-hosts ip-address
ip_address
•
For an entire network:
sensor(config-NetworkAccess-gen)# never-shun-networks ip-address
ip_address
netmask
netmask
Step 6
Exit general submode:
sensor(config-NetworkAccess-gen)# exit
sensor(config-NetworkAccess)# exit
Apply Changes:?[yes]:
Step 7
Type yes to apply changes.
Configuring Logical Devices
You must set up logical devices for the other hardware that the senor will manage.
The logical devices contain userid, password and enable password information.
For example, routers that all share the same passwords and usernames can be
under one logical device name.
Caution
You MUST have a logical device created before configuring the blocking device.
To set up logical devices, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Enter Network Access mode:
sensor(config)# service networkAccess
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...