Appendix B Troubleshooting
Troubleshooting the 4200 Series Appliance
B-22
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Step 8
If the network device is using SSH-DES or SSH-3DES, make sure the you have
enabled SSH connections to the device.
See
Enabling SSH Connections to the Network Device, page B-24
, for the
procedure.
Step 9
Verify that each interface/direction on each controlled device is correct.
See
Verifying the Interfaces/Directions on the Network Device, page B-23
, for the
procedure.
Device Access Issues
NAC may not be able to access the devices it is managing. Make sure the you have
the correct IP address and username and password for the managed devices and
the correct interface/direction configured.
To troubleshoot device access issues, follow these steps:
Step 1
Log in to the CLI.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Enter service configuration mode for NetworkAccess:
sensor (config)# service NetworkAccess
Step 4
Verify the IP address for the managed devices:
sensor(config-NetworkAccess)# show settings
cat6k-devices (min: 0, max: 100, current: 1)
communication:
ip-address: 172.21.172.151
nat-address:
shun-device-cfg: groupa shun-interfaces (min: 0, max: 100, current: 2)
post-vacl-name: testPostACL
pre-vacl-name: testPreACL vlan: 1 units: none post-vacl-name:
pre-vacl-name:
lan: 5 units: none
general
————————————
allow-sensor-shun: false
enable-acl-logging: false
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...