Misconfigured Access List - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Troubleshooting the 4200 Series Appliance
Make sure the IP address of the workstation that is trying to connect to the sensor is permitted in the
Step 5
sensor's access list:
sensor# setup
--- System Configuration Dialog ---
At any point you may enter a question mark '?' for help.
User ctrl-c to abort configuration dialog at any prompt.
Default settings are in square brackets '[]'.
Current Configuration:
service host
network-settings
host-ip 10.89.130.108/23,10.89.130.1
host-name sensor
telnet-option enabled
access-list 0.0.0.0/0
ftp-timeout 300
no login-banner-text
exit
--MORE--
If the workstation's network address is permitted in the sensor's access list, go to Step 6.
Add a permit entry for the workstation's network address, save the configuration, and try to connect
Step 6
again.
For more information, see
Make sure the network configuration allows the workstation to connect to the sensor.
Step 7
If the sensor is protected behind a firewall and the workstation is in front of the firewall, make sure the
firewall is configured to allow the workstation to access the sensor. Or if the workstation is behind a
firewall that is performing network address translation on the workstation's IP address, and the sensor is
in front of the firewall, make sure that the sensor's access list contains a permit entry for the
workstation's translated address.
For more information, see

Misconfigured Access List

To correct a misconfigured access list, follow these steps:
Log in to the CLI.
Step 1
View your configuration to see the access list:
Step 2
sensor# show configuration | include access-list
access-list 10.0.0.0/8
access-list 64.0.0.0/8
sensor#
Verify that the client IP address is listed in the allowed networks. If it is not, add it:
Step 3
sensor# configure terminal
sensor(config)# service host
sensor(config-hos)# network-settings
sensor(config-hos-net)# access-list 171.69.70.0/24
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
C-6
Changing the Access List, page
Changing the Access List, page
Appendix C
4-5.
4-5.
Troubleshooting
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents