Appendix A Intrusion Detection System Architecture
System Architectural Details
A-48
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Remote applications can send commands to the sensor through RDEP. The remote
client sends an RDEP control transaction to the sensor’s WebServer, which passes
it to the Control Transaction Server. The Control Transaction Server passes the
control transaction through IDAPI to the appropriate application, waits for the
application’s response, and then returns the result.
Figure A-6
shows remote
applications sending commands to the sensor through RDEP.
Figure A-6
Sending Commands Through RDEP
Sensor Directory Structure
IDS 4.x has the following directory structure:
•
/usr/cids/idsRoot—Main installation directory.
•
/usr/cids/idsRoot/shared—Stores files used during system recovery.
•
/usr/cids/idsRoot/var—Stores files created dynamically while the sensor is
running.
•
/usr/cids/idsRoot/var/updates—Stores files and logs for update installations.
•
/usr/cids/idsRoot/var/virtualSensor—Stores files used by SensorApp to
analyze regular expressions.
119107
RDEP
Client
IDAPI
Application
Sensor
CT Request
CT Response
CT Server
WebServer
CT
Response
CT Request
CT Response
HTTP
POST
IEV, IDS-MC, Third Party Event
Management Applications
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...