10-69
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
Step 3
Enter network access mode:
sensor(config)# service networkAccess
Step 4
Set the IP address for the router controlled by NAC:
sensor(config-NetworkAccess)# router-devices ip-address
ip_address
Step 5
Type the logical device name that you created in
Configuring Logical Devices,
page 10-66
.
sensor(config-NetworkAccess-rou)# shun-device-cfg
logical_device_name
NAC accepts anything you type. It does not check to see if the logical device
exists.
Step 6
Designate the method used to access the sensor:
sensor(config-NetworkAccess-rou)# communication
telnet/ssh-des/ssh-3des
If unspecified, SSH 3DES is used.
Note
If you are using DES or 3DES, you must use the command ssh host-key
ip_address to accept the key or NAC cannot connect to the device.
Step 7
Specify the sensor’s NAT address:
sensor(config-NetworkAccess-rou)# nat-address
nat_address
Note
This changes the IP address in the first line of the ACL from the sensor’s
address to the NAT address.
Step 8
Set the interface direction:
sensor(config-NetworkAccess-rou-shu)# shun-interfaces direction
in or
out
interface-name
interface name you want ACL attached to
Step 9
Add the preShun ACL name (optional):
sensor(config-NetworkAccess-rou-shu)# pre-acl-name
pre_shun_acl_name
Step 10
Add the postShun ACL name (optional):
sensor(config-NetworkAccess-rou-shu)# post-acl-name
post_shun_acl_name
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...