System Components
Figure A-2
Sensor
Master Blocking Sensor
A NAC application instance can control 0, 1, or many network devices. NAC does
Note
not share control of any network device with other NAC applications, IDS
management software, other network management software, or system
administrators. Only one NAC application instance is allowed to run on a given
sensor.
NAC initiates a block in response to one of the following:
•
•
•
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
A-18
NAC Application
Routers-PIX Firewalls
Block
Subscription
Block Event
NAC
Block CT
Block CT
Response
Routers-PIX Firewalls
Block CT
NAC
Block CT
Response
An alert event generated from a signature that is configured with a block
action
A block configured manually through the CLI, IDM, or the IDS MC
A block configured permanently against a host or network address
Appendix A
Intrusion Detection System Architecture
Block
Subscription
Block Event
IDAPI
Block CT
Block CT
Response
Block CT
Block CT
IDAPI
Block CT
Response
EventStore
CT Source
Block CT
Response
Web Server
CT Server
78-15597-02
Need help?
Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?
Questions and answers