Appendix B Troubleshooting
Troubleshooting the 4200 Series Appliance
B-26
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Verifying the Master Blocking Sensor Configuration
To verify that a master blocking sensor (MBS) is set up properly or to troubleshoot
an MBS that is not set up properly, you can use the show statistics
networkAccess command. Make sure that the forwarding sensor is set up as TLS
trusted host if the remote MBS is using TLS for web access.
To verify a sensor’s NAC MBS configuration, follow these steps:
Step 1
View the NAC’s statistics and verify that the MBS entries are in the statistics:
sensor# show statistics networkAccess
Current Configuration
AllowSensorShun = false
ShunMaxEntries = 250
MasterBlockingSensor
SensorIp = 10.89.149.46
SensorPort = 443
UseTls = 1
State
ShunEnable = true
ShunnedAddr
Host
IP = 122.122.122.44
ShunMinutes = 60
MinutesRemaining = 59
Step 2
If the MBS does not show up in the statistics, you need to add it.
See
Configuring the Sensor to be a Master Blocking Sensor, page 10-73
, for the
procedure.
Step 3
Initiate a manual block to a bogus host IP address to make sure the MBS is
initialing blocks:
a.
Enter configuration mode:
sensor# configure terminal
b.
Enter the NAC’s service configuration mode:
sensor(config)# service NetworkAccess
c.
Enter general NAC configuration mode:
sensor(config-NetworkAccess)# general
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...