A-29
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix A Intrusion Detection System Architecture
System Components
appropriate RDEP response message in an HTTP response. If the remote HTTP
server is a CIDS WebServer, the WebServer uses the Transaction Server servlet to
process the remote control transactions.
The transactionHandlerLoop returns either the RDEP response or a failure
response as the control transaction’s response to the remote control transaction’s
initiator. If the HTTP server returns an unauthorized status response (indicating
the HTTP client has insufficient credentials on the HTTP server), the
transactionHandlerLoop reissues the transaction request using
TransactionSource’s designated username and password to authenticate the
requestor’s identity. The transactionHandlerLoop continues to loop until it
receives a control transaction that directs it to exit or until its exit event is
signaled.
WebServer
The WebServer provides configuration support for IDM. It also provides IDS
RDEP, which enables the sensor to report security events, receive IDIOM
transactions, and serve IP logs.
The WebServer supports HTTP 1.0 and 1.1. The communications with the
WebServer often include sensitive information, such as passwords, that would
severely compromise the security of the system if an attacker were able to
eavesdrop. For this reason, sensors ship with TLS enabled. The TLS protocol is
an encryption protocol that is compatible with SSL.
CLI
The CLI provides the sensor user interface for all direct node access such as
Telnet, SSH, and serial interface. You configure the sensor applications with the
CLI. Direct access to the underlying OS is allowed through the service role.
This section contains the following topics:
•
User Account Roles, page A-30
•
CLI Behavior, page A-32
•
Service Account, page A-31
•
Regular Expression Syntax, page A-34
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...