Chapter 10 Configuring the Sensor Using the CLI
IDSM-2 Configuration Tasks
10-94
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Note
Refer to Catalyst 6500 Series Switch Command Reference for more
information on trunk ports and ACLs.
Cisco IOS Software
To set VACLs to capture IDS traffic on VLANs, follow these steps:
Step 1
Log in to the console.
Step 2
Enter privileged mode.
Router# configure terminal
Step 3
Define the ACL:
Router (config)# ip access-list {
standard
|
extended
}
acl_name
Create ACL entries through the permit and/or deny statements:
Router(config-ext-nacl)# ?
Ext Access List configuration commands:
default Set a command to its defaults
deny Specify packets to reject
dynamic Specify a DYNAMIC list of PERMITs or DENYs
evaluate Evaluate an access list
exit Exit from access-list configuration mode
no Negate a command or set its defaults
permit Specify packets to forward
remark Access list entry comment
Router(config-ext-nacl)# exit
Step 4
Define the VLAN access map:
Router(config)# vlan access-map
map_name
[0-65535]
Step 5
Configure a match clause in a VLAN access map sequence:
Router (config-access-map)# match {ip address {1-199 | 1300-2699 |
acl_name
}
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...