10-75
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
Step 10
Specify the port number for the host’s HTTP communications.
sensor(config-networkAccess-gen-mas)# mbs-port
port_number
The default is 80/443 if not specified.
Step 11
Set the status of whether or not the host uses TLS/SSL:
sensor(config-networkAccess-gen-mas)# mbs-tls
true/false
Note
If you set the value to true, you need to use the command tls trusted-host
ip-address mbs_ip_address.
Step 12
Exit master blocking sensor submode:
sensor(config-NetworkAccess-gen-mas)# exit
sensor(config-NetworkAccess-gen)# exit
sensor(config-NetworkAccess)# exit
sensor(config)# exit
Apply Changes:?[yes]:
Step 13
Type yes to apply changes.
Obtaining a List of Blocked Hosts and Connections
You can obtain a list of blocked hosts and blocked connections by using the show
statistics command for NetworkAccess.
To obtain a list of blocked hosts and connections, follow these steps:
Step 1
Log in to the CLI.
Step 2
Check the statistics for NAC:
sensor# show statistics networkAccess
Current Configuration
AllowSensorShun = false
ShunMaxEntries = 250
NetDevice
Type = Cisco
IP = 10.89.150.160
NATAddr = 0.0.0.0
Communications = telnet
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...