Chapter 10 Configuring the Sensor Using the CLI
IDSM-2 Configuration Tasks
10-92
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Step 3
Set the source interfaces/VLANs for the monitor session:
Router (config)# monitor session {
session_number
} {source {interface
type
slot_number/port_number
} | {vlan
vlan_ID
}} [, | - | rx | tx |
both]
Step 4
Enable an IDSM-2 data port as a SPAN destination:
Router (config)# monitor session {
session_number
} {destination
intrusion-detection-module
module_number
data-port
data_port_number
Step 5
If you want to disable the monitor session:
Router (config)# no monitor session
session_number
Step 6
To filter the SPAN session so that only certain VLANs are seen from switch port
trunks (optional):
Router (config)# monitor session {
session_number
} {filter {
vlan_ID
} [,
| - ]}
Step 7
Exit configuration mode:
Router (config)# exit
Step 8
To show current monitor sessions:
Router # show monitor session
session_number
Note
Refer to the Catalyst 6500 Series Cisco IOS Command Reference for
more information on SPAN.
Configuring VACLS to Capture IDS Traffic
You can set VACLs to capture traffic for IDS from a single VLAN or from
multiple VLANs. This section describes how to configure VACLs to capture IDS
traffic.
This section contains the following topics:
•
Catalyst Software, page 10-93
•
Cisco IOS Software, page 10-94
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...