Appendix A Intrusion Detection System Architecture
System Overview
A-6
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
•
Update IDS.
You can schedule automatic updates or request that updates be applied
immediately to the applications and signature data files.
•
Retrieve information.
You can retrieve data (status, error, and alert messages) and iplogs from the
system. You can also retrieve statistics and diagnostic information.
New Features in Version 4.x
The following new features appear in the IDS 4.x system architecture:
•
XML documents replace tokens and configuration files.
Sensor configuration, control, log, and event information are communicated
and stored in XML documents as directed by the IDIOM specification.
•
RDEP replaces postoffice protocol.
RDEP uses HTTP/HTTPS protocol to deliver XML documents between the
sensor and external systems. postoffice operated by pushing alarms and
queuing up to 1000 on each sensor. The RDEP client pulls alerts from the
sensor and there is less of a chance of missing alerts.
•
Version 4.x is now an open system.
Note
“Open” refers to the fact that we provide specifications so that you
can write applications to configure the sensor and/or monitor the
events generated by the sensor.
Alarms and configuration are communicated using RDEP and IDIOM, which
are based on the HTTP/HTTPS and XML open standards. Providing a secure,
open system that uses standard communication protocols allows greater
internal and third party integration.
•
Version 4.x offers the following scalability enhancements:
–
Provides gigabit sensing
–
Addresses the scaling and performance limitations that are inherent in the
postoffice architecture
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...