Appendix B Troubleshooting
Troubleshooting the 4200 Series Appliance
B-10
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Access List Misconfiguration
To correct a misconfigured access list, follow these steps:
Step 1
Log in to the CLI.
Step 2
View your configuration to see the access list:
sensor# show configuration | include accessList
accessList ipAddress 10.0.0.0 netmask 255.0.0.0
accessList ipAddress 10.89.0.0 netmask 255.255.0.0
accessList ipAddress 64.101.0.0 netmask 255.255.0.0
accessList ipAddress 10.89.149.31 netmask 255.255.255.255
accessList ipAddress 64.102.0.0 netmask 255.255.0.0
Step 3
Verify that the client IP address is listed in the allowed networks. If it is not, add it:
sensor# configure terminal
sensor(config)# service Host
sensor(config-Host)# networkParams
sensor(config-Host-net)# accessList ipAddress
value
netmask
value
Duplicate IP Address Shuts Interface Down
If you have two newly imaged sensors with the same IP address that come up on
the same network at the same time, the interface shuts down. Linux prevents the
command and control interface Ethernet port from activating if it detects an
address conflict with another host.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...