B-19
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix B Troubleshooting
Troubleshooting the 4200 Series Appliance
3.
Verify that the EventAction is set to shunHost for specific signatures.
See
Blocking Not Occurring for a Signature, page B-25
, for the procedure.
4.
Verify that the MBS is properly configured.
See
Verifying the Master Blocking Sensor Configuration, page B-26
.
Note
See
NAC, page A-16
, for a discussion of NAC architecture.
This section provides troubleshooting help for blocking and the NAC service.
This section contains the following topics.
•
Verifying NAC is Running, page B-19
•
Verifying NAC is Connecting, page B-20
•
Device Access Issues, page B-22
•
Verifying the Interfaces/Directions on the Network Device, page B-23
•
Enabling SSH Connections to the Network Device, page B-24
•
Blocking Not Occurring for a Signature, page B-25
•
Verifying the Master Blocking Sensor Configuration, page B-26
Verifying NAC is Running
To verify that NAC is running, use the show version command.
Step 1
Log in to the CLI.
Step 2
Verify that NAC is running:
sensor# show version
Application Partition:
Cisco Systems Intrusion Detection Sensor, Version 4.1(3)S61
OS Version 2.4.18-5smpbigphys
Platform: IDS-4235
Sensor up-time is 20 days.
Using 214319104 out of 921522176 bytes of available memory (23% usage)
Using 596M out of 15G bytes of available disk space (5% usage)
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...