Configuring Authentication On The Sensor; Managing Tls And Ssh Trust Relationships - Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual

Intrusion detection system appliance and module
Table of Contents

Advertisement

System Components
AuthenticationApp
Authenticating Users
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
A-12
Alert generation module (AGM)—Processes all requests for alert event
generation. The AGM then generates the appropriate alert messages and
presents them to the IDAPI interface. The AGM also issues TCP resets,
routing of packets to be logged for IP session logins, and notification to the
Network Access Controller (NAC) for blocks.
Configuration management module (CMM)—Maintains the sensor's
configuration.
AuthenticationApp has the following responsibilities:
To authenticate a user's identity
To administrate the user's accounts, privileges, keys, and certificates
To configure which authentication methods are used by AuthenticationApp
and other access services on the sensor
This section contains the following topics:
Authenticating Users, page A-12
Configuring Authentication on the Sensor, page A-13
Managing TLS and SSH Trust Relationships, page A-14
When a user tries to access the sensor through a service such as the WebServer or
the CLI, the user's identity must be authenticated and the user's privileges must
be established. The service that is providing access to the user initiates an
execAuthenticateUser control transaction request to AuthenticationApp to
authenticate the user's identity. The control transaction request typically includes
the username and a password, or the user's identity can be authenticated using an
SSH authorized key.
AuthenticationApp responds to the execAuthenticateUser control transaction
request by attempting to authenticate the user's identity. AuthenticationApp
returns a control transaction response that contains the user's authentication status
and privileges. If the user's identity cannot be authenticated, AuthenticationApp
returns an unauthenticated status and anonymous user privileges in the control
transaction response. The control transaction response also indicates if the
Appendix A
Intrusion Detection System Architecture
78-15597-02

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?

Questions and answers

Table of Contents