Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual page 268

Intrusion detection system appliance and module
Table of Contents

Advertisement

Sensor Configuration Tasks
Configuring the Sensor to Manage a Cisco PIX Firewall
Step 1
Step 2
Step 3
Step 4
Step 5
Step 6
Step 7
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
10-72
To configure the sensor to manage a Cisco PIX Firewall, follow these steps:
Log in to the CLI using an account with administrator privileges.
Enter configuration mode:
sensor# configure terminal
Enter network access mode:
sensor(config)# service networkAccess
Set the IP address for the router controlled by NAC:
sensor(config-NetworkAccess)# pix-devices ip-address
Type the logical device name that you created in
page
10-66.
sensor(config-NetworkAccess-pix)# shun-device-cfg
NAC accepts anything you type. It does not check to see if the logical device
exists.
Designate the method used to access the sensor:
sensor(config-NetworkAccess-pix)# communication
If unspecified, SSH 3DES is used.
Note
If you are using DES or 3DES, you must use the command ssh host-key
ip_address to accept the key or NAC cannot connect to the device.
Specify the sensor's NAT address:
sensor(config-NetworkAccess-pix)# nat-address
Note
This changes the IP address in the first line of the ACL from the sensor's
address to the NAT address.
Chapter 10
Configuring the Sensor Using the CLI
ip_address
Configuring Logical Devices,
logical_device_name
telnet/ssh-des/ssh-3des
nat_address
78-15597-02

Advertisement

Table of Contents
loading

Table of Contents