Configuring Addresses Never To Block - Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual

Intrusion detection system appliance and module
Table of Contents

Advertisement

Chapter 10
Configuring the Sensor Using the CLI
Step 8

Configuring Addresses Never to Block

Step 1
Step 2
Step 3
Step 4
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Type yes to apply changes.
There is a time delay while the signatures are updated.
Note
You must tune your sensor to identify hosts and networks that should never be
blocked, not even manually, because you may have a trusted network device
whose normal, expected behavior appears to be an attack. Such a device should
never be blocked, and trusted, internal networks should never be blocked.
You can specify a single host or an entire network.
If you specify a netmask, this is the netmask of the network that should never be
blocked. If no netmask is specified, only the IP address you specify will never be
blocked.
To set up addresses never to be blocked by blocking devices, follow these steps:
Log in to the CLI using an account with administrator privileges.
Enter configuration mode:
sensor# configure terminal
Enter network access mode:
sensor(config)# service networkAccess
Enter general submode:
sensor(config-NetworkAccess)# general
Sensor Configuration Tasks
10-65

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?

Questions and answers

Table of Contents