Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual page 26

Intrusion detection system appliance and module
Table of Contents

Advertisement

Appliances
Introducing the Appliance
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
1-2
Appliance Restrictions, page 1-9
Setting Up a Terminal Server, page 1-9
The appliance is a high-performance, plug-and-play device. The appliance is a
component of the Intrusion Detection System (IDS), a network-based, real-time
intrusion detection system. See
supported appliances.
You can use the Command Line Interface (CLI), IDS Device Manager, or
Management Center for IDS Sensors to configure the appliance. Refer to your
IDS manager documentation. To access IDS documentation on Cisco.com, refer
to Cisco Intrusion Detection System (IDS) Hardware and Software Version 4.1
Documentation Guide that shipped with your appliance.
You can configure the appliance to respond to recognized signatures as it captures
and analyzes network traffic. These responses include logging the event,
forwarding the event to the IDS manager, performing a TCP reset, generating an
IP log, capturing the alert trigger packet, and/or reconfiguring a router.
After being installed at key points in the network, the appliance monitors and
performs real-time analysis of network traffic by looking for anomalies and
misuse based on an extensive, embedded signature library. When the system
detects unauthorized activity, appliances can terminate the specific connection,
permanently block the attacking host, log the incident, and send an alert to the IDS
manager. Other legitimate connections continue to operate independently without
interruption.
Appliances can also monitor and analyze syslog messages from Cisco routers to
detect and report network security policy violations.
Appliances are optimized for specific data rates and are packaged in Ethernet,
Fast Ethernet, and Gigabit Ethernet configurations. In switched environments,
appliances must be connected to the switch's Switched Port Analyzer (SPAN) port
or VLAN Access Control list (VACL) capture port.
Chapter 1
Supported Sensors, page
Introducing the Sensor
1-16, for a list of
78-15597-02

Advertisement

Table of Contents
loading

Table of Contents