
28
Software Troubleshooting
Procedure 11
Procedure steps
Step
Action
1
Manually add the following variable to provide raw snort
configuration via the user interface.
USER_CONF
2
Apply the policy to store data in the variable $USER_CONFathe
the following location:
/var/sf/detection_engines/[uuid]/user.conf
--End--
Verifying prohibit packet data on the DC
Use this procedure to verify prohibit packet data on the DC.
Procedure 12
Procedure steps
Step
Action
1
Register a 4.7 IS sensor to the DC.
2
Select the Prohibit Packet Data from Sensor option at the
registration screen.
3
On the managed sensor or IS, ensure that the following line
ignore_packet_data 1
is present in:
/var/sf/peers/[DC UUID]/ids_forward.conf
If the parameter ignore_packet_data is set to 1, then the prohibit
packet data on DC is done properly.
--End--
Performing RNA IP/Port Exclusion
Use this procedure for RNA IP/Port Exclusion
Procedure 13
Procedure steps
Step
Action
1
Configure the RNA detection policy and apply the policy.
2
Run the traffic to see the RNA events and flow events for the
particular ports and IPs.
Nortel TPS 4.7
Threat Protection System Troubleshooting Guide
NN47240-700
01.01
Standard
1
1
2007
Copyright © 2007 Nortel Networks
.
Содержание 2070
Страница 55: ......