Blocking Not Occurring For A Signature - Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual

Intrusion detection system appliance and module
Table of Contents

Advertisement

Appendix B
Troubleshooting
Step 3
Step 4

Blocking Not Occurring for a Signature

Step 1
Step 2
Step 3
Step 4
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Enable SSH:
sensor(config)# ssh host
Type yes when prompted to accept the device.
If blocking is not occurring for a specific signature, check that the EventAction is
set to shunHost.
To make sure blocking is occurring for a specific signature, follow these steps:
Log in to the CLI.
Enter configuration mode:
sensor# configure terminal
Enter virtual sensor mode:
sensor(config)# service virtual-sensor-configuration virtualSensor
Make sure the EventAction is set to shunHost:
sensor(config-vsc)# tune-micro-engines
sensor(config-vsc-virtualSensor)# atomic.icmp
sensor(config-vsc-virtualSensor-ATO)# sig sigid 2000
sensor(config-vsc-virtualSensor-ATO-sig)# show settings
SIGID: 2000 <protected>
SubSig: 0 <protected>
AlarmDelayTimer:
AlarmInterval:
AlarmSeverity: informational <defaulted>
AlarmThrottle: Summarize <defaulted>
AlarmTraits:
CapturePacket: False <defaulted>
ChokeThreshold: 100 <defaulted>
DstIpAddr:
DstIpMask:
Enabled: False <defaulted>
EventAction: shunHost
Troubleshooting the 4200 Series Appliance
blocking_device_ip_ address
B-25

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?

Questions and answers

Table of Contents