Configuring Cisco Ids Interfaces On The Router - Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual

Intrusion detection system appliance and module
Table of Contents

Advertisement

NM-CIDS Configuration Tasks

Configuring Cisco IDS Interfaces on the Router

Step 1
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
10-78
This section contains the following topics:
Configuring Cisco IDS Interfaces on the Router, page 10-78
Establishing Cisco IDS Console Sessions, page 10-80
Rebooting the NM-CIDS, page 10-83
Setting Up Packet Capture, page 10-84
Checking the Status of the Cisco IDS Software, page 10-85
Supported Cisco IOS Commands, page 10-86
The NM-CIDS differs from a standalone appliance because it does not have an
external console port. Console access to the NM-CIDS is enabled when you issue
the command service-module ids-module slot_number/0 session on the router, or
when you initiate a Telnet connection into the router with the port number
corresponding to the NM-CIDS slot. The lack of an external console port means
that the initial bootup configuration is possible only through the router.
When you issue the command service-module ids-sensor slot_number/0 session,
you create a console session with the NM-CIDS, in which you can issue any IDS
configuration commands. After completing work in the session and exiting the
IDS CLI, you are returned to Cisco IOS CLI.
The session command starts a reverse Telnet connection using the IP address of
the ids-sensor interface. The ids-sensor interface is an interface between the
NM-CIDS and the router. You must assign an IP address to the ids-sensor
interface before invoking the session command. Assigning a routable IP address
can make the IDS interface itself vulnerable to attacks. To counter that
vulnerability, a loopback IP address is assigned to the ids-sensor interface.
To set up the NM-CIDS interfaces, follow these steps:
Confirm the NM-CIDS slot number in your router:
Router # show interfaces ids-sensor
You can also use the show run command. Look for "IDS-Sensor" and the
Note
slot number.
Chapter 10
Configuring the Sensor Using the CLI
slot_number
/0
78-15597-02

Advertisement

Table of Contents
loading

Table of Contents