Verifying The Interfaces And Directions On The Network Device; Enabling Ssh Connections To The Network Device - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Chapter A
Troubleshooting
For More Information
For the procedure for verifying the interfaces and directions for each network device, see
Interfaces and Directions on the Network Device, page

Verifying the Interfaces and Directions on the Network Device

To verify that each interface and direction on each controlled device is correct, you can send a manual
block to a bogus host and then check to see if deny entries exist for the blocked addresses in the ACL of
the router.
To perform a manual block using IDM, choose Monitoring > Sensor Monitoring > Time-Based
Note
Actions > Host Blocks. To perform a manual block using IME, choose Configuration >
sensor_name > Sensor Monitoring > Time-Based Actions > Host Blocks.
To initiate a manual block to a bogus host, follow these steps:
Step 1
Enter ARC general submode.
sensor# configure terminal
sensor(config)# service network-access
sensor(config-net)# general
Step 2
Start the manual block of the bogus host IP address.
sensor(config-net-gen)# block-hosts 10.16.0.0
Step 3
Exit general submode.
sensor(config-net-gen)# exit
sensor(config-net)# exit
Apply Changes:? [yes]:
Press Enter to apply the changes or type
Step 4
Telnet to the router and verify that a deny entry for the blocked address exists in the router ACL. Refer
Step 5
to the router documentation for the procedure.
Remove the manual block by repeating Steps 1 through 4 except in Step 2 place no in front of the
Step 6
command.
sensor(config-net-gen)# no block-hosts 10.16.0.0

Enabling SSH Connections to the Network Device

If you are using SSH-DES or SSH-3DES as the communication protocol for the network device, you
must make sure you have enabled it on the device.
To enable SSH connections to the network device, follow these steps:
Log in to the CLI.
Step 1
Enter configuration mode:
Step 2
sensor# configure terminal
OL-18504-01
to discard them.
no
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
Troubleshooting the Appliance
A-43.
Verifying the
A-43

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents