Logging All Blocking Events And Errors - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 10
Configuring Blocking
Verify that writing to NVRAM is disabled:
Step 7
sensor(config-net-gen)# show settings
general
-----------------------------------------------
Step 8
Exit network access submode:
sensor(config-net-gen)# exit
sensor(config-net)# exit
Apply Changes:?[yes]:
Step 9
Press Enter to apply the changes or type

Logging All Blocking Events and Errors

Use the log-all-block-events-and-errors [true | false] command in the service network access submode
to configure the sensor to log events that follow blocks from start to finish. For example, when a block
is added to or removed from a device, an event is logged. You may not want all of these events and errors
to be logged. Disabling log-all-block-events-and-errors suppresses the new events and errors. The
default is enabled.
To disable blocking event and error logging, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter network access mode:
sensor# configure terminal
sensor(config)# service network-access
Enter general submode:
Step 3
sensor(config-net)# general
Disable blocking event and error logging:
Step 4
sensor(config-net-gen)# log-all-block-events-and-errors false
Step 5
Verify that logging is disabled:
sensor(config-net-gen)# show settings
general
-----------------------------------------------
78-16527-01
log-all-block-events-and-errors: true <defaulted>
enable-nvram-write: false default: false
enable-acl-logging: false default: false
allow-sensor-block: false <defaulted>
block-enable: true <defaulted>
block-max-entries: 250 <defaulted>
max-interfaces: 250 <defaulted>
master-blocking-sensors (min: 0, max: 100, current: 0)
-----------------------------------------------
log-all-block-events-and-errors: false default: true
enable-nvram-write: false default: false
enable-acl-logging: false default: false
allow-sensor-block: false <defaulted>
block-enable: true <defaulted>
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Configuring Blocking Properties
10-13

Advertisement

Table of Contents
loading

Table of Contents