Troubleshooting the 4200 Series Appliance
Unable to See Alerts
Step 1
Step 2
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
B-14
If you cannot see alerts, the following:
Make sure the signature is enabled.
•
Make sure the sensor is seeing packets.
•
•
Make sure that alerts are being generated.
Make sure Event Viewer can communicate with the sensor.
•
To make sure you can see alerts, follow these steps:
Log in to the CLI.
Make sure the signature is enabled:
Enter configuration mode:
a.
sensor# configure terminal
b.
Enter virtual sensor mode:
sensor(config)# service virtual-sensor-configuration virtualSensor
Make sure the signature is enabled:
c.
sensor(config-vsc)# tune-micro-engines
sensor(config-vsc-virtualSensor# atomic.icmp
sensor(config-vsc-virtualSensor-ATO)# sig sigid 2000
sensor(config-vsc-virtualSensor-ATO-sig)# show settings
SIGID: 2000 <protected>
SubSig: 0 <protected>
AlarmDelayTimer:
AlarmInterval:
AlarmSeverity: informational <defaulted>
AlarmThrottle: Summarize <defaulted>
AlarmTraits:
CapturePacket: False <defaulted>
ChokeThreshold: 100 <defaulted>
DstIpAddr:
DstIpMask: Enabled: False <defaulted>
Appendix B
Troubleshooting
78-15597-02
Need help?
Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?
Questions and answers