Chapter 10
Configuring Blocking
Blocking Prerequisites
Before you configure blocking, make sure you do the following:
•
Caution
Two sensors cannot control blocking on the same device. If this situation is needed, configure one sensor
as the master blocking sensor to manage the devices and the other sensors can forward their block
requests to the master blocking sensor. For the procedure, see
Blocking Sensor, page
•
•
•
•
Supported Blocking Devices
By default, Network Access Controller supports up to 250 devices in any combination. The following
devices are supported by Network Access Controller:
•
•
•
•
78-16527-01
Analyze your network topology to understand which devices should be blocked by which sensor,
and which addresses should never be blocked.
10-25.
Gather the usernames, device passwords, enable passwords, and connections types (Telnet or SSH)
needed to log in to each device.
Know the interface names on the devices.
Know the names of the Pre-Block ACL or VACL and Post-Block ACL or VACL if needed.
Understand which interfaces should and should not be blocked and in which direction (in or out).
You do not want to accidentally shut down an entire network.
Cisco series routers using Cisco IOS 11.2 or later (ACLs):
Cisco 1600 series router
–
Cisco 1700 series router
–
Cisco 2500 series router
–
Cisco 2600 series router
–
Cisco 2800 series router
–
–
Cisco 3600 series router
–
Cisco 3800 series router
–
Cisco 7200 series router
Cisco 7500 series router
–
Catalyst 5000 switches with RSM with IOS 11.2(9)P or later (ACLs)
Catalyst 6500 switches and 7600 routers with IOS 12.1(13)E or later (ACLs)
Catalyst 6500 switches 7600 routers with Catalyst software version 7.5(1) or later (VACLs)
Supervisor Engine 1A with PFC
–
Supervisor Engine 1A with MSFC1
–
Supervisor Engine 1A with MFSC2
–
Supervisor Engine 2 with MSFC2
–
Supervisor Engine 720 with MSFC3
–
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Blocking Prerequisites
Configuring the Sensor to be a Master
10-3
Need help?
Do you have a question about the 4215 - Intrusion Detection Sys Sensor and is the answer not in the manual?
Questions and answers