Chapter 1 Introducing the Sensor
Modules
1-14
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
In addition to analyzing captured packets to identify malicious activity, the
NM-CIDS can also perform IP session logging that can be configured as a
response action on a per-signature basis. When the signature fires, session logs are
created over a specified time period in a TCPDump format. You can view these
logs using Ethereal or replay the IP session using tools such as TCP Replay.
Note
The NM-CIDS does not support sending syslog messages to a syslog server if
there is an intrusion event, nor does it support Simple Network Management
Protocol (SNMP) traps.
You can manage and retrieve events from the NM-CIDS through the CLI or
through one of these IDS managers—IDS Device Manager or Management
Center for IDS Sensors. For instructions on accessing IDS documentation on
Cisco.com, refer to Cisco Intrusion Detection System (IDS) Hardware and
Software Version 4.1 Documentation Guide that shipped with your NM-CIDS.
The IDS requires a reliable time source. All the events (alerts) must have the
correct time stamp, otherwise, you cannot correctly analyze the logs after an
attack. You cannot manually set the time on the NM-CIDS. The NM-CIDS gets
its time from the Cisco router in which it is installed. Routers do not have a battery
so they cannot preserve a time setting when they are powered off. You must set
the router’s clock each time you power up or reset the router, or you can configure
the router to use NTP time synchronization. We recommend NTP time
synchronization. You can configure either the NM-CIDS itself or the router it is
installed in to use NTP time synchronization. See
Setting the Time on Sensors,
page 1-18
, for more information.
Introducing the Cisco Catalyst 6500 Series Intrusion Detection
System Services Module
The Cisco Catalyst 6500 Series Intrusion Detection System Services Module
(IDSM-2) is a switching module that performs intrusion detection in the Catalyst
6500 series switch. You can use the CLI, IDS Device Manager, or Management
Center for IDS Sensors to configure the IDSM-2. For instructions on accessing the
IDS documentation on Cisco.com, refer to the Cisco Intrusion Detection System
(IDS) Hardware and Software Version 4.1 Documentation Guide that shipped
with your IDSM-2.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...