A-7
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix A Intrusion Detection System Architecture
System Components
–
Changes from a push to a pull model that enables management consoles
to support more sensors
–
Provides better support for large scale sensor deployment and
management
•
Version 4.x has the following security enhancements:
–
The CLI replaces the OS shell access.
–
Multi-user support with multi-level permissions (administrator, operator,
viewer, service) replaces the former single netrangr account.
•
The hardened Linux OS replaces the Solaris OS.
•
A memory-mapped circular buffer EventStore replaces log files and log file
maintenance (no more sapd).
•
Supported Cisco management options are the CLI, the IDM or IDS MC,
which replace CSPM and the UNIX Director.
•
The following reliability enhancements:
–
Alarms are not lost because of communication failures.
–
CLI configuration instead of native shell configuration decreases the
possibility of misconfiguration. The sensor has become a true appliance
rather than a group of applications running on a workstation.
•
Version 4.x builds an infrastructure to support the future IDS roadmap, which
includes:
–
Multiple interfaces and VLANs per sensor
–
AAA authentication
–
False positive reduction
–
Inline intrusion prevention
System Components
This section describes IDS components in more detail.
This section contains the following topics:
•
MainApp, page A-8
•
SensorApp, page A-11
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...