B-33
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix B Troubleshooting
Troubleshooting the 4200 Series Appliance
Note
Make sure that your /etc/syslog.conf has that facility enabled at the proper
priority.
Caution
The syslog is much slower than logApp (on the order of 50 messages per second
as opposed to 1000 or so). We recommend that you enable debug severity on one
zone at a time.
NTP
When you configure an NTP server to provide the time for the sensor, the sensor
runs the ntpdate utility to synchronize with the NTP server. A defect exists that
lets the sensor do this without authenticating. If you have not correctly typed the
NTP authentication key ID and values, the sensor NTP updates still appear to be
working. However, the long term updates from the NTP server will not occur if
the authentication key ID and values are not correctly configured.
Also, if you are trying to configure NTP on the sensor and receive the following
error, there are two possible causes:
Error: Could not run ntpdate utility. Fatal Error has occurred. Node
MUST be rebooted to enable alarming.
Either there is a connectivity problem or you have encountered an NTP
reconfiguration defect.
This section contains the following topics:
•
Verifying that the Sensor is Synchronized with the NTP Server, page B-34
•
NTP Server Connectivity Problem, page B-35
•
NTP Reconfiguration Defect, page B-35
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...