Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual page 198

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring the Sensor to be a Master Blocking Sensor
On the blocking forwarding sensor, configure it to accept the X.509 certificate of the master
b.
blocking sensor:
sensor(config-web)# exit
sensor(config)# tls trusted-host ip-address mbs_ip_address port port_number
Example:
sensor(config)# tls trusted-host ip-address 10.0.0.0 port 8080
Certificate MD5 fingerprint is
F4:4A:14:BA:84:F4:51:D0:A4:E2:15:38:7E:77:96:D8Certificate SHA1 fingerprint is
84:09:B6:85:C5:43:60:5B:37:1E:6D:31:6A:30:5F:7E:4D:4D:E8:B2
Would you like to add this to the trusted certificate table for this host?[yes]:
Note
Type
Step 4
Enter network access mode:
Step 5
sensor(config)# service network-access
Enter general submode:
Step 6
sensor(config-net)# general
Add a master blocking sensor entry:
Step 7
sensor(config-net-gen)# master-blocking-sensors mbs_ip_address
Specify the username for an administrative account on the master blocking sensor host:
Step 8
sensor(config-net-gen-mas)# username username
Step 9
Specify the password for the user:
sensor(config-net-gen-mas)# password
Enter password []: *****
Re-enter mbs-password []: *****
sensor(config-net-gen-mas)#
Specify the port number for the host's HTTP communications.
Step 10
sensor(config-net-gen-mas)# port port_number
The default is 80/443 if not specified.
Set the status of whether or not the host uses TLS/SSL:
Step 11
sensor(config-net-gen-mas)# tls [true | false]
sensor(config-net-gen-mas)
Note
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
10-26
You are prompted to accept the certificate based on the certificate's fingerprint. Sensors provide
only self-signed certificates (instead of certificates signed by a recognized certificate authority).
You can verify the master blocking sensor host sensor's certificate by logging in to the host
sensor and typing the show tls fingerprint command to see that the host certificate's fingerprints
match.
to accept the certificate from the master blocking sensor.
yes
If you set the value to true, you need to use the command tls trusted-host ip-address
mbs_ip_address.
Chapter 10
Configuring Blocking
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents