Chapter 10 Configuring the Sensor Using the CLI
NM-CIDS Configuration Tasks
10-78
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
This section contains the following topics:
•
Configuring Cisco IDS Interfaces on the Router, page 10-78
•
Establishing Cisco IDS Console Sessions, page 10-80
•
Rebooting the NM-CIDS, page 10-83
•
Setting Up Packet Capture, page 10-84
•
Checking the Status of the Cisco IDS Software, page 10-85
•
Supported Cisco IOS Commands, page 10-86
Configuring Cisco IDS Interfaces on the Router
The NM-CIDS differs from a standalone appliance because it does not have an
external console port. Console access to the NM-CIDS is enabled when you issue
the command service-module ids-module slot_number/0 session on the router, or
when you initiate a Telnet connection into the router with the port number
corresponding to the NM-CIDS slot. The lack of an external console port means
that the initial bootup configuration is possible only through the router.
When you issue the command service-module ids-sensor slot_number/0 session,
you create a console session with the NM-CIDS, in which you can issue any IDS
configuration commands. After completing work in the session and exiting the
IDS CLI, you are returned to Cisco IOS CLI.
The session command starts a reverse Telnet connection using the IP address of
the ids-sensor interface. The ids-sensor interface is an interface between the
NM-CIDS and the router. You must assign an IP address to the ids-sensor
interface before invoking the session command. Assigning a routable IP address
can make the IDS interface itself vulnerable to attacks. To counter that
vulnerability, a loopback IP address is assigned to the ids-sensor interface.
To set up the NM-CIDS interfaces, follow these steps:
Step 1
Confirm the NM-CIDS slot number in your router:
Router # show interfaces ids-sensor
slot_number
/0
Note
You can also use the show run command. Look for “IDS-Sensor” and the
slot number.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...