Switches And Vacls; Routers - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 10
Configuring Blocking
Note
Set the interface name and direction:
Step 7
sensor(config-net-rou)# block-interfaces interface_name [in | out]
The name of the interface must either be the complete name of the interface or an abbreviation that the
Caution
router recognizes with the interface command.
(Optional) Add the pre-ACL name:
Step 8
sensor(config-net-rou-blo)# pre-acl-name pre_acl_name
(Optional) Add the post-ACL name:
Step 9
sensor(config-net-rou-blo)# post-acl-name post_acl_name
Exit network access submode:
Step 10
sensor(config-net-rou-blo)# exit
sensor(config-net-rou)# exit
sensor(config-net)# exit
sensor(config)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 11
Configuring the Sensor to Manage Catalyst 6500 Series Switches and Cisco
7600 Series Routers
This section describes how to configure the sensor to manage Cisco switches. It contains the following
topics:

Switches and VACLs

You can configure Network Access Controller to block using VACLs on the switch itself when running
Cisco Catalyst software, or to block using router ACLs on the MSFC or on the switch itself when running
Cisco IOS software. This section describes blocking using VACLs. For blocking using the router ACLS
see
You must configure the blocking interfaces on the Catalyst 6500 series switch and specify the VLAN of
traffic you want blocked.
78-16527-01
This changes the IP address in the first line of the ACL from the sensor's address to the NAT
address. This is not a NAT address configured on the device being managed. It is the address the
sensor is translated to by an intermediate device, one that is between the sensor and the device
being managed.
Switches and VACLs, page 10-21
Configuring the Sensor to Manage Catalyst 6500 Series Switches and Cisco 7600 Series Routers,
page 10-22
Configuring the Sensor to Manage Cisco Routers, page
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
10-19.
Configuring Blocking Devices
10-21

Advertisement

Table of Contents
loading

Table of Contents