Introducing The Nme Ips - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Chapter 1
Introducing the Sensor
Figure 1-9
Destination traffic
The IDSM2 searches for patterns of misuse by examining either the data portion and/or the header
portion of network packets. Content-based attacks contain potentially malicious data in the packet
payload, whereas, context-based attacks contain potentially malicious data in the packet headers.
You can configure the IDSM2 to generate an alert when it detects potential attacks. Additionally, you
can configure the IDSM2 to transmit TCP resets on the source VLAN, generate an IP log, and/or initiate
blocking countermeasures on a firewall or other managed device. Alerts are generated by the IDSM2
through the Catalyst 6500 series switch backplane to the IPS manager, where they are logged or
displayed on a graphical user interface.
For More Information

Introducing the NME IPS

Cisco Intrusion Prevention System Network Module (NME IPS) integrates and brings inline Cisco IPS
functionality to Cisco access routers. You can install the NME IPS in any one of the network module
slots in the 2800 and 3800 series router.
The NME IPS has its own operating system, Cisco IPS software, startup, and run-time configurations.
You launch and configure the modules through the router by means of a configuration session on the
modules. After the session, you return to the router CLI and clear the session.
For the NME IPS, all management traffic passes through the external FastEthernet interface on the
module. Management traffic includes all communications between applications, such as IDM, IME,
CSM, and CS-MARS, and the servers on the module for exchange of IPS events, IP logs, configuration,
and control messages.
OL-18504-01
IDSM2 Block Diagram
Source traffic
For more information on installing the IDSM2, see
For more information on configuring the IDSM2 to receive IPS traffic, refer to
IDSM2.
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
Cisco 6500 switch
Switch
backplane Copied VACL traffic
or SPAN traffic to
IDSM-2 monitor port
IDSM-2
Alarms and configuration through
IDSM-2 command and control port
IPS management console
Installing the IDSM2, page
IPS Modules
Destination traffic
Source traffic
7-5.
Configuring the
1-25

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents