Network Access Controller; About Network Access Controller - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

MainApp
server handles the remote control transaction and returns the appropriate RDEP response message in an
HTTP response. If the remote HTTP server is an IPS web server, the web server uses the CtlTransSource
servlet to process the remote control transactions.
The transactionHandlerLoop returns either the RDEP response or a failure response as the control
transaction's response to the remote control transaction's initiator. If the HTTP server returns an
unauthorized status response (indicating the HTTP client has insufficient credentials on the HTTP
server), the transactionHandlerLoop reissues the transaction request using CtlTransSource's designated
username and password to authenticate the requestor's identity. The transactionHandlerLoop continues
to loop until it receives a control transaction that directs it to exit or until its exit event is signaled.

Network Access Controller

This section describes Network Access Controller, which is the IPS application that starts and stops
blocks on routers, switches, and firewalls. A block is an entry in a device's configuration or ACL to block
incoming and outgoing traffic for a specific host IP address or network address.
This section contains the following topics:

About Network Access Controller

Network Access Controller's main responsibility is to block events. When it responds to a block, it either
interacts with the devices it is managing directly to enable the block or it sends a block request through
the Control Transaction Server to a master blocking sensor. The Web Server on the master blocking
sensor receives the control transaction and passes it to the Control Transaction Server, which passes it
to the Network Access Controller. Network Access Controller on the master blocking sensor then
interacts with the devices it is managing to enable the block.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
A-12
About Network Access Controller, page A-12
Network Access Controller Features, page A-13
Supported Blocking Devices, page A-15
ACLs and VACLs, page A-16
Maintaining State Across Restarts, page A-16
Connection-Based and Unconditional Blocking, page A-17
Blocking with Cisco Firewalls, page A-18
Blocking with Catalyst Switches, page A-19
Appendix A
System Architecture
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents