Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual page 27

Intrusion detection system appliance and module
Table of Contents

Advertisement

Chapter 1
Introducing the Sensor
How the Appliance Functions
Note
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
This section explains how the appliance captures network traffic.
Each appliance comes with at least two interfaces. In a typical installation, one
interface monitors (sniffs) the desired network segment, and the other interface
(command and control) communicates with the IDS manager and other network
devices. The monitoring interface is in promiscuous mode, meaning it has no IP
address and is not visible on the monitored segment.
With the addition of the 4-port Fast Ethernet NIC card, the IDS-4235, IDS-4250,
and the IDS-4215 have six interfaces. With the addition of the 2-port XL card, the
IDS-4250 has four interfaces. With the addition of the SX card, the IDS-4250 has
three interfaces.
The command and control interface is always Ethernet. This interface has an
assigned IP address, which allows it to communicate with the IDS manager
workstation or network devices (typically a Cisco router). Because this interface
is visible on the network, you should use encryption to maintain data privacy.
Secure Shell (SSH) is used to protect the Command Line Interface (CLI) and the
Transaction Layer Security/Secure Sockets Layer (TLS/SSL) is used to protect
the IDS manager workstation. Both SSH and TLS/SSL are enabled by default on
the IDS manager workstations.
When responding to attacks, the appliance can do the following:
Insert TCP resets via the monitoring interface.
The TCP reset action is only appropriate as an action selection on
Note
those signatures that are associated with a TCP-based service. If
selected as an action on non-TCP-based services, no action is taken.
Additionally, TCP resets are not guaranteed to tear down an offending
session because of limitations in the TCP protocol. On the
IDS-4250-XL, TCP resets are sent through the TCP Reset interface.
Make access control list (ACL) changes on routers that the appliance
manages.
Appliances
1-3

Advertisement

Table of Contents
loading

Table of Contents