10-67
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
Step 4
Create the logical device name:
sensor(config-NetworkAccess)# shun-device-cfg name
logical_device_name
Step 5
Type the username for that logical device:
sensor(config-NetworkAccess-shu)# username
username
Type none if there is no username.
Step 6
Specify the password for the user:
sensor(config-NetworkAccess-shu)# password
Enter password[]: ****
Re-enter password
Type none if there is no password.
Step 7
Specify the enable password for the user:
sensor(config-NetworkAccess-shu)# enable-password
Enter enable-password[]: ****
Re-enter enable-password
Type none if there is no enable password.
Step 8
Exit shun device configuration submode:
sensor(config-NetworkAccess-shu)# exit
sensor(config-NetworkAccess)# exit
Apply Changes:?[yes]:
Step 9
Type yes to apply changes.
Configuring Blocking Devices
NAC uses ACLs on Cisco routers and switches to manage those devices. These
ACLs are built as follows:
1.
A
permit
line with the sensor’s IP address, or if specified, the NAT address
Note
If you permit the sensor to be blocked, this line does not appear in the
ACL.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...