Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-74
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
To configure the NAC on a sensor to forward blocks to an MBS, follow these
steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Configure the NAC of the blocking forwarding sensor to accept the TLS/SSL
X.509 certificate of the MBS remote host (in configuration mode):
sensor(config)# tls trusted-host ip-address
MBS_ip_address
Note
You are prompted to accept the certificate based on the certificate’s
fingerprint. Sensors provide only self-signed certificates (instead of
certificates signed by a recognized certificate authority). You can verify
the MBS host sensor’s certificate by logging in to the host sensor and
typing the show tls fingerprint command to see that the host certificate’s
fingerprints match.
Step 4
Accept the certificates for all MBS hosts that the NAC will connect with.
Step 5
Enter network access mode:
sensor(config)# service networkAccess
Step 6
Enter general submode:
sensor(config-NetworkAccess)# general
Step 7
Add an MBS entry:
sensor(config-networkAccess-gen)# master-blocking-sensors
mbs-ipaddress
mbs_host_ip_address
Step 8
Specify the username for an administrative account on the MBS host:
sensor(config-networkAccess-gen-mas)# mbs-username
username
Step 9
Specify the password for the user:
sensor(config-networkAccess-gen-mas)# mbs-password
Enter mbs-password []: *****
Re-enter mbs-password []: *****
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...