Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-68
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
2.
PreShun ACL (if specified)
This ACL must already exist on the device.
3.
Any active blocks
4.
Either:
–
PostShun ACL (if specified)
This ACL must already exist on the device.
Note
Make sure the last line in the ACL is
permit ip any any
.
–
permit ip any any
(not used if a PostShun ACL is specified)
NAC uses two ACLs to manage devices. Only one is active at any one time. It uses
the offline ACL name to build the new ACL, then applies it to the interface. NAC
then reverses the process on the next cycle.
Caution
A single sensor can manage multiple devices, but you cannot use multiple sensors
to control a single device. In this case, use a master blocking sensor. See
Configuring the Sensor to be a Master Blocking Sensor, page 10-73
, for more
information.
This section contains the following topics:
•
Configuring the Sensor to Manage a Cisco Router, page 10-68
•
Configuring the Sensor to Manager a Catalyst 6500 Series Switch,
page 10-70
•
Configuring the Sensor to Manage a Cisco PIX Firewall, page 10-72
Configuring the Sensor to Manage a Cisco Router
To configure a sensor to manager a Cisco router, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter configuration mode:
sensor# configure terminal
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...