
38
Troubleshooting Global Faults
cd /var/tmp
mkdir logdir
snort -dvei bond 0 (fp1:fp2) -b -l logdir
The preceding command will result in a log file as follows:
snort.log.1135279299
4
Enter the following series of commands for a packet capture
with tcpdump. Set the parameter snaplento 0, to catch whole
packets.
cd /var/tmp
tcpdump -I bond0 (fp1:fp2) -s0 -w pcapfile
--End--
Troubleshooting memory problems
This section describes the process of troubleshooting memory problems.
To track memory issues, the maintenance tool
RPM
must be installed. Once
installed the tool does not harm the system.
Procedure 28
Procedure steps
Action
Run the following command to install the RPM that collects data
for troubleshooting performance issues.
rpm -I Sourcefire_Maintenance_Tools-0.1.0-1.i386.
rpm
Running the preceding command adds a modified version of top
that logs output to the following location every 60 seconds.
/var/log/top.log
IPS mode cable Deployment Scenarios
This section describes the various IPS mode cable deployment scenarios.
Deploying between two endpoints
•
Use two straight through cables to deploy the IPS between 2 end
points. No special cabling is needed.
•
The sensor supports auto MDI/MDI-X so the link will be negotiated
properly when the sensor is in the normal operational state.
•
When the sensor is placed into bypass mode it internally implements a
crossover and allows normal operation of the connection.
Nortel TPS 4.7
Threat Protection System Troubleshooting Guide
NN47240-700
01.01
Standard
1
1
2007
Copyright © 2007 Nortel Networks
.
Содержание 2070
Страница 55: ......