Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual page 258

Intrusion detection system appliance and module
Table of Contents

Advertisement

Sensor Configuration Tasks
Disabling Blocking
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Step 7
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
10-62
By default, blocking is enabled on the sensor. If NAC is managing a device and
you need to manually configure something on that device, you should disable
blocking first. You want to avoid a situation in which both you and NAC could be
making a change at the same time on the same device. This could cause the device
and/or NAC to crash.
To disable blocking, follow these steps:
Log in to the CLI using an account with administrator privileges.
Enter configuration mode:
sensor# configure terminal
Enter network access mode:
sensor(config)# service networkAccess
Enter general submode:
sensor(config-NetworkAccess)# general
Disable blocking on the sensor:
sensor(config-NetworkAccess-gen)# shun-enable false
By default, this value is true.
Exit general submode:
sensor(config-NetworkAccess-gen)# exit
sensor(config-NetworkAccess)# exit
Apply Changes:?[yes]:
Type yes to apply changes.
Note
To enable blocking, follow the steps but change the value in Step 5 from
false to true.
Chapter 10
Configuring the Sensor Using the CLI
78-15597-02

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?

Questions and answers

Table of Contents