Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-72
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Configuring the Sensor to Manage a Cisco PIX Firewall
To configure the sensor to manage a Cisco PIX Firewall, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Enter network access mode:
sensor(config)# service networkAccess
Step 4
Set the IP address for the router controlled by NAC:
sensor(config-NetworkAccess)# pix-devices ip-address
ip_address
Step 5
Type the logical device name that you created in
Configuring Logical Devices,
page 10-66
.
sensor(config-NetworkAccess-pix)# shun-device-cfg
logical_device_name
NAC accepts anything you type. It does not check to see if the logical device
exists.
Step 6
Designate the method used to access the sensor:
sensor(config-NetworkAccess-pix)# communication
telnet/ssh-des/ssh-3des
If unspecified, SSH 3DES is used.
Note
If you are using DES or 3DES, you must use the command ssh host-key
ip_address to accept the key or NAC cannot connect to the device.
Step 7
Specify the sensor’s NAT address:
sensor(config-NetworkAccess-pix)# nat-address
nat_address
Note
This changes the IP address in the first line of the ACL from the sensor’s
address to the NAT address.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...