Chapter 10
Configuring the Sensor Using the CLI
Allowing the Sensor to Block Itself
Caution
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Step 7
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
We recommend that you do not permit the sensor to block itself, because it may
stop communicating with the blocking device. You can configure this option if
you can ensure that if the sensor creates a rule to block its own IP address, it will
not prevent the sensor from accessing the blocking device.
To allow the sensor to block itself, follow these steps:
Log in to the CLI using an account with administrator privileges.
Enter configuration mode:
sensor# configure terminal
Enter network access mode:
sensor(config)# service networkAccess
Enter general submode:
sensor(config-NetworkAccess)# general
Configure the sensor to block itself:
sensor(config-NetworkAccess-gen)# allow-sensor-shun true
By default, this value is false.
Exit general submode:
sensor(config-NetworkAccess-gen)# exit
sensor(config-NetworkAccess)# exit
Apply Changes:?[yes]:
Type yes to apply changes.
To reverse this procedure, follow the steps but change the value in Step 5
Note
from true to false.
Sensor Configuration Tasks
10-61
Need help?
Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?
Questions and answers