Appendix A Intrusion Detection System Architecture
Summary of Applications
A-50
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Table A-2
Summary of Applications
Application
Description
AuthenticationApp
Authorizes and authenticates users based on IP
address, password, and/or digital certificates.
CLI
Accepts command line input and modifies the
local configuration using IDAPI.
IDS Event Viewer (IEV)
1
Subscribes to intrusion, network access, status,
and error events and displays the event
information in a GUI.
EventServer
2
Accepts RDEP request for events from remote
clients.
MainApp
Reads the configuration and starts
applications, handles starting and stopping of
applications and node reboots, handles
software upgrades.
NetworkAccessControllerApp
(NAC)
3
A NAC is run on every sensor. Each NAC
subscribes to network access events from its
local EventStore. The NAC configuration
contains a list of sensors and the network
access devices that its local NAC controls. If a
NAC is configured to send network access
events to a master blocking sensor, it initiates
a network access control transaction to the
remote NAC that controls the device. These
network access action control transactions are
also used by IDS managers to issue occasional
network access actions.
SensorApp
4
Captures and analyzes traffic on the monitored
network and generates intrusion and network
access events. Responds to IP logging control
transactions that turn logging on and off and
that send and delete IP log files.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...