Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual page 356

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

System Overview
Figure A-1
Figure A-1
SNMP
IDM
Master
Blocking
Sensor
Monitored
Network
IPS software includes the following applications:
Each application has its own configuration file in XML format.
Note
MainApp—Initializes the system, starts and stops the other applications, configures the OS, and
performs upgrades. It contains the following components:
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
A-2
illustrates the system design.
System Design
FTP
SNMP
NotificationApp
AuthenticationApp
Network Access Controller
InterfaceApp
LogApp
HTTPS
Web Server
CtlTransSource
CIDS
- Signature Definition
Ethernet
- Event Action Rules
ctlTransSource (Control Transaction server)—Allows sensors to send control transactions. This
is used to enable the Network Access Controller's master blocking sensor capability.
Event Store—An indexed store used to store IPS events (error, status, and alert system
messages) that is accessible through the CLI, IDM, ASDM, or RDEP.
InterfaceApp—Handles bypass and physical settings and defines paired interfaces. Physical
settings are speed, duplex, and administrative state.
LogApp—Writes all the application's log messages to the log file and the application's error
messages to the Event Store.
Network Access Controller—Manages remote network devices (firewalls, routers, and
switches) to provide blocking capabilities when an alert event has occurred. Network Access
Controller creates and applies ACLs on the controlled network device or uses the shun
command (firewalls).
NotificationApp—Sends SNMP traps when triggered by alert, status, and error events.
NotificationApp uses the public domain SNMP agent. SNMP GETs provide information about
the general health of the sensor.
Web Server (HTTP RDEP2 server)—Provides a web interface and communication with other
IPS devices through RDEP2 using several servlets to provide IPS services.
SCP
NTP
MainApp
SensorApp
Appendix A
System Architecture
Event Store
CLI
IDAPI
Telnet
SSH
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents