Chapter 10 Configuring the Sensor Using the CLI
IDSM-2 Configuration Tasks
10-96
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Using the mls ip ids Command for Capturing IDS Traffic
This section describes how to use the mls ip ids command to capture IDS traffic.
This section contains the following topics:
•
Catalyst Software, page 10-96
•
Cisco IOS Software, page 10-97
Catalyst Software
When you are running the Cisco IOS Firewall on the Multilayer Switch Feature
Card (MSFC), you cannot use VACLs to capture traffic for the IDSM-2, because
you cannot apply VACLs to a VLAN in which you have applied an IP inspect rule
for the Cisco IOS Firewall. However, you can use the mls ip ids command to
designate which packets are captured. Packets that are permitted by the ACL are
captured. Those denied by the ACL are not captured. The permit/deny parameter
does not affect whether a packet is forwarded to destination ports. Packets coming
into that router interface are checked against the IDS ACL to determine if they
should be captured. The mls ip ids command is applied as part of the MSFC
configuration instead of the supervisor configuration. The mls ip ids command
only captures incoming traffic. You will need to use the mls ip ids command on
both the client side router interface and server side router interface, so that both
directions of the connection will be captured.
To use the mls ip ids command to capture IDS traffic, follow these steps:
Step 1
Log in to the MSFC.
Step 2
Enter privileged mode:
Router> enable
Step 3
Enter configuration mode:
Router# configure terminal
Step 4
Configure an ACL to designate which packets will be captured:
Router(config)# ip access-list extended
word
Step 5
Select the interface that carries the packets to be captured:
Router(config)# interface
interface_name
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...