Chapter 10
Configuring the Sensor Using the CLI
Configure an action clause in the VLAN access map sequence to accompany the
Step 6
preceding match clause:
Router(config-access-map)# action forward capture
Step 7
Apply the VLAN access-map to the specified VLANs:
Router (config)# vlan filter
Configure the IDSM-2 data ports to capture the captured-flagged traffic:
Step 8
Router (config)# intrusion-detection module
data_port_number
Step 9
Enable the capture function on the IDSM-2:
Router (config)# intrusion-detection module
data_port_number
You should not configure an IDSM-2 data port as both a SPAN destination port
Caution
and a capture port.
This example shows the output from the show run command:
Router# show run
intrusion-detection module 4 data-port 1 capture allowed-vlan
450,1002-1005
intrusion-detection module 4 data-port 1 capture
.
.
.
vlan access-map CAPTUREALL 10
match ip address MATCHALL
action forward capture
.
.
.
ip access-list extended MATCHALL
permit ip any any
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
map_name
capture allowed-vlan
capture
IDSM-2 Configuration Tasks
vlan_list
vlan-list
module_number
capture_vlans
module_number
data-port
data-port
10-95
Need help?
Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?
Questions and answers