Time And The Sensor; Time Sources And The Sensor - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Time and the Sensor

Time and the Sensor
This section describes how to maintain accurate time on the sensor, and contains the following topics:

Time Sources and the Sensor

The sensor requires a reliable time source. All events (alerts) must have the correct UTC and local time
stamp, otherwise, you cannot correctly analyze the logs after an attack. When you initialize the sensor,
you set up the time zones and summertime settings. This section provides a summary of the various ways
to set the time on sensors.
We recommend that you use an NTP server. You can use authenticated or unauthenticated NTP. For
Note
authenticated NTP, you must obtain the NTP server IP address, NTP server key ID, and the key value
from the NTP server. You can set up NTP during initialization or you can configure NTP through the
CLI, IDM, IME, or ASDM.
The Appliances
The IDSM2
The AIM IPS and the NME IPS
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
A-16
Time Sources and the Sensor, page A-16
Synchronizing IPS Module Clocks with Parent Device Clocks, page A-17
Verifying the Sensor is Synchronized with the NTP Server, page A-17
Correcting Time on the Sensor, page A-18
Use the clock set command to set the time. This is the default.
Configure the appliance to get its time from an NTP time synchronization source.
The IDSM2 can automatically synchronize its clock with the switch time. This is the default. The
UTC time is synchronized between the switch and the IDSM2. The time zone and summertime
settings are not synchronized between the switch and the IDSM2.
Be sure to set the time zone and summertime settings on both the switch and the IDSM2 to
Note
ensure that the UTC time settings are correct. The local time of the IDSM2 could be
incorrect if the time zone and/or summertime settings do not match between the IDSM2 and
the switch.
Configure the IDSM2 to get its time from an NTP time synchronization source.
The AIM IPS and the NME IPS can automatically synchronize their clock with the clock in the
router chassis in which they are installed (parent router). This is the default. The UTC time is
synchronized between the parent router and the AIM IPS and the NME IPS. The time zone and
summertime settings are not synchronized between the parent router and the AIM IPS and the
NME IPS.
Chapter A
Troubleshooting
OL-18504-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents