10-97
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
IDSM-2 Configuration Tasks
Step 6
Apply the ACL created in Step 4 to the interface selected in Step 5:
Router(config-if)# mls ip ids
word
Step 7
Log in to the supervisor engine.
Step 8
Enter privileged mode.
Console> enable
Step 9
On the supervisor engine, add the IDSM-2 monitoring port (port 7 or 8) to the
VACL capture list:
Console> (enable) set security acl capture
idsm_module
/
port_number
Caution
For the IDSM-2 to capture all packets marked by the mls ip ids command, port 7
or 8 of the IDSM-2 must be a member of all VLANs to which those packets are
routed.
Cisco IOS Software
When you are using ports as router interfaces rather than switch ports, there is no
VLAN on which to apply a VACL.
You can use the mls ip ids command to designate which packets will be captured.
Packets that are permitted by the ACL will be captured. Those denied by the ACL
will not be captured. The permit/deny parameter does not affect whether a packet
is forwarded to destination ports. Packets coming into that router interface are
checked against the IDS ACL to determine if they should be captured.
To use the mls ip ids command to capture IDS traffic, follow these steps:
Step 1
Log in to the console.
Step 2
Enter privileged mode:
Router> enable
Step 3
Enter configuration mode:
Router# configure terminal
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...