B-25
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix B Troubleshooting
Troubleshooting the 4200 Series Appliance
Step 3
Enable SSH:
sensor(config)# ssh host
blocking_device_ip_ address
Step 4
Type
yes
when prompted to accept the device.
Blocking Not Occurring for a Signature
If blocking is not occurring for a specific signature, check that the EventAction is
set to shunHost.
To make sure blocking is occurring for a specific signature, follow these steps:
Step 1
Log in to the CLI.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Enter virtual sensor mode:
sensor(config)# service virtual-sensor-configuration virtualSensor
Step 4
Make sure the EventAction is set to shunHost:
sensor(config-vsc)# tune-micro-engines
sensor(config-vsc-virtualSensor)# atomic.icmp
sensor(config-vsc-virtualSensor-ATO)# sig sigid 2000
sensor(config-vsc-virtualSensor-ATO-sig)# show settings
SIGID: 2000 <protected>
SubSig: 0 <protected>
AlarmDelayTimer:
AlarmInterval:
AlarmSeverity: informational <defaulted>
AlarmThrottle: Summarize <defaulted>
AlarmTraits:
CapturePacket: False <defaulted>
ChokeThreshold: 100 <defaulted>
DstIpAddr:
DstIpMask:
Enabled: False <defaulted>
EventAction: shunHost
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...