Appendix A Intrusion Detection System Architecture
System Components
A-12
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
•
Alert generation module (AGM)—Processes all requests for alert event
generation. The AGM then generates the appropriate alert messages and
presents them to the IDAPI interface. The AGM also issues TCP resets,
routing of packets to be logged for IP session logins, and notification to the
Network Access Controller (NAC) for blocks.
•
Configuration management module (CMM)—Maintains the sensor’s
configuration.
AuthenticationApp
AuthenticationApp has the following responsibilities:
•
To authenticate a user’s identity
•
To administrate the user’s accounts, privileges, keys, and certificates
•
To configure which authentication methods are used by AuthenticationApp
and other access services on the sensor
This section contains the following topics:
•
Authenticating Users, page A-12
•
Configuring Authentication on the Sensor, page A-13
•
Managing TLS and SSH Trust Relationships, page A-14
Authenticating Users
When a user tries to access the sensor through a service such as the WebServer or
the CLI, the user’s identity must be authenticated and the user’s privileges must
be established. The service that is providing access to the user initiates an
execAuthenticateUser control transaction request to AuthenticationApp to
authenticate the user’s identity. The control transaction request typically includes
the username and a password, or the user’s identity can be authenticated using an
SSH authorized key.
AuthenticationApp responds to the execAuthenticateUser control transaction
request by attempting to authenticate the user’s identity. AuthenticationApp
returns a control transaction response that contains the user’s authentication status
and privileges. If the user’s identity cannot be authenticated, AuthenticationApp
returns an unauthenticated status and anonymous user privileges in the control
transaction response. The control transaction response also indicates if the
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...