Supported Blocking Devices - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix A
System Architecture

Supported Blocking Devices

Network Access Controller can control the following devices:
78-16527-01
Maintaining blocking state across network device restarts
Network Access Controller reapplies blocks and removes expired blocks as needed whenever a
network device is shut down and restarted. Network Access Controller is not affected by
simultaneous or overlapping shutdowns and restarts of Network Access Controller.
Authentication and authorization
Network Access Controller can establish a communications session with a network device that uses
AAA authentication and authorization including the use of remote TACACS+ servers.
Two types of blocking
Network Access Controller supports host blocks and network blocks. Host blocks are connection
based or unconditional. Network blocks are always unconditional.
For more information, see
NAT addressing
Network Access Controller can control network devices that use a NAT address for the sensor. If
you specify a NAT address when you configure a network device, that address is used instead of the
local IP address when the sensor address is filtered from blocks on that device.
Single point of control
Network Access Controller does not share control of network devices with administrators or other
software. If you must update a configuration, shut down Network Access Controller until the change
is complete. You can enable or disable Network Access Controller through the CLI or any IPS
manager. When Network Access Controller is reenabled, it completely reinitializes itself, including
rereading the current configuration for each controlled network device.
We recommend that you disable Network Access Controller from blocking when you are
Note
configuring any network device, including firewalls.
Maintains up to 250 active blocks at any given time
Network Access Controller can maintain up to 250 active blocks at a time. Although Network
Access Controller can support up to 65535 blocks, we recommend that you allow no more than 250
at a time.
Note
The number of blocks is not the same as the number of interface and directions.
Cisco routers running Cisco IOS 11.2 or later
Catalyst 5000 series switches with Supervisor Engine software 5.3(1) or later running on the
supervisor engine, and IOS 11.2(9)P or later running on the RSM.
You must have the RSM because blocking is performed on the RSM.
Note
Catalyst 6000 series switches with PFC installed running Catalyst software 5.3 or later
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Connection-Based and Unconditional Blocking, page
MainApp
A-17.
A-15

Advertisement

Table of Contents
loading

Table of Contents