Displaying And Generating The Server Certificate; Installing The License Key - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 4
Initial Configuration Tasks
Verify the entry was removed from the trusted host list:
Step 7
sensor(config)# exit
sensor# show tls trusted-hosts
No entries
The IP address no longer appears in the list:

Displaying and Generating the Server Certificate

A TLS certificate is generated when the sensor is first started. Use the tls generate-key command to
generate a new server self-signed X.509 certificate.
The sensor's IP address is included in the certificate. If you change the sensor's IP address, the sensor
Note
automatically generates a new certificate.
The new certificate replaces the existing certificate, which requires you to update the trusted hosts lists
Caution
on remote systems with the new certificate so that future connections succeed. You can update the trusted
hosts lists on remote IPS sensors using the tls trusted-host command. For the procedure, see
TLS Trusted Hosts, page
hosts lists on the remote sensors that are sending block requests to the master blocking sensor.
To generate a new TLS certificate, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Generate the new certificate:
Step 2
sensor# tls generate-key
MD5 fingerprint is FD:83:6E:41:D3:88:48:1F:44:7F:AF:5D:52:60:89:DE
SHA1 fingerprint is 4A:2B:79:A0:82:8B:65:3A:83:B5:D9:50:C0:8E:F6:C6:B0:30:47:BB
Verify that the key was generated:
Step 3
sensor# show tls fingerprint
MD5: FD:83:6E:41:D3:88:48:1F:44:7F:AF:5D:52:60:89:DE
SHA1: 4A:2B:79:A0:82:8B:65:3A:83:B5:D9:50:C0:8E:F6:C6:B0:30:47:BB
sensor#

Installing the License Key

Although the sensor functions without the license, you must have a license to obtain signature updates.
To obtain a license, you must have a Cisco Service for IPS contract. Contact your reseller, Cisco service
or product sales to purchase a contract.
78-16527-01
4-35. If the sensor is a master blocking sensor, you must update the trusted
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Installing the License Key
Adding
4-37

Advertisement

Table of Contents
loading

Table of Contents