A-31
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix A Intrusion Detection System Architecture
System Components
•
Viewer—This user role has the lowest level of privileges.
Viewers can perform all viewing operations such as viewing events and
viewing some configuration files. Their only available administrative
operation is changing their passwords.
Tip
Monitoring applications only require viewer access to the sensor. You can use the
CLI to set up a user account with viewer privileges and then configure the
monitoring application to use this account to connect to the sensor.
•
Service—This user role does not have direct access to the CLI. Service
account users are logged directly into a bash shell rather than the CLI shell.
See
Service Account, page A-31
, for more information.
Service Account
The service account is a support and troubleshooting tool that enables TAC to log
in to a native operating system shell rather than the CLI shell. It does not exist on
the sensor by default. You must create it so that it available for TAC to use for
troubleshooting your sensor. See
Creating the Service Account, page 10-12
, for
the procedure to create the service account.
Only one service account is allowed per sensor and only one account is allowed a
service role. When the service account’s password is set or reset, the root
account’s password is set to the same password. This allows the service account
user to su to root using the same password. When the service account is removed,
the root account’s password is locked.
The service account is not intended to be used for configuration purposes. Only
modifications made to the sensor through the service account under the direction
of TAC are supported. Cisco Systems does not support the addition and/or running
of an additional service to the operating system through the service account,
because it affects proper performance and proper functioning of the other IDS
services. TAC does not support a sensor on which additional services have been
added.
You can track logins to the service account by checking the log file /var/log/.tac,
which is updated with a record of service account logins.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...