Appendix B Troubleshooting
Troubleshooting the 4200 Series Appliance
B-14
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Unable to See Alerts
If you cannot see alerts, the following:
•
Make sure the signature is enabled.
•
Make sure the sensor is seeing packets.
•
Make sure that alerts are being generated.
•
Make sure Event Viewer can communicate with the sensor.
To make sure you can see alerts, follow these steps:
Step 1
Log in to the CLI.
Step 2
Make sure the signature is enabled:
a.
Enter configuration mode:
sensor# configure terminal
b.
Enter virtual sensor mode:
sensor(config)# service virtual-sensor-configuration virtualSensor
c.
Make sure the signature is enabled:
sensor(config-vsc)# tune-micro-engines
sensor(config-vsc-virtualSensor# atomic.icmp
sensor(config-vsc-virtualSensor-ATO)# sig sigid 2000
sensor(config-vsc-virtualSensor-ATO-sig)# show settings
SIGID: 2000 <protected>
SubSig: 0 <protected>
AlarmDelayTimer:
AlarmInterval:
AlarmSeverity: informational <defaulted>
AlarmThrottle: Summarize <defaulted>
AlarmTraits:
CapturePacket: False <defaulted>
ChokeThreshold: 100 <defaulted>
DstIpAddr:
DstIpMask: Enabled: False <defaulted>
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...