Configuring The Catalyst Series 6500 Switch For Idsm-2 In Promiscuous Mode; Using The Tcp Reset Interface - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 15
Configuring IDSM-2
idsm-2# exit
[Connection to 127.0.0.91 closed by foreign host]
router#
Initialize IDSM-2 if you have not yet done so.
Step 5
For the procedure, see
Configuring the Catalyst Series 6500 Switch for IDSM-2 in
Promiscuous Mode
Traffic is captured for promiscuous analysis on IDSM-2 through SPAN or VACL capture. Port 1
(GigabitEthernet0/1) is used as the TCP reset port, port 2 (GigabitEthernet0/2) is the command and
control port, and ports 7 and 8 (GigabitEthernet0/7 and GigabitEthernet0/8) are the monitoring ports.
You can configure both monitoring ports to be either SPAN destination ports or VACL capture ports.
If you configure both ports as monitoring ports, make sure that they are configured to monitor different
Caution
traffic.
You should not configure an IDSM-2 data port as both a SPAN destination port and a VACL capture port,
Caution
because IDSM-2 will not receive traffic. This dual configuration (SPAN and VACL) causes problems on
the switch and traffic is not sent properly.
Note
Prior to Catalyst Software 8.4(3), IDSM-2 data ports defaulted to trunking all VLANs. In Catalyst
Software 8.4(3) and later, IDSM-2 data ports default to trunking no VLANs. Make sure that the IDSM-2
ports are trunking the proper VLANs, especially if you upgrading from pre-8.4(3) to 8.4(3) or later.
This section contains the following topics:

Using the TCP Reset Interface

The IDSM-2 has a TCP reset interface—port 1. The IDSM-2 has a specific TCP reset interface because
it cannot send TCP resets on its sensing ports.
78-16527-01
Initializing the Sensor, page
Using the TCP Reset Interface, page 15-7
Configuring SPAN, page 15-8
Configuring VACLS, page 15-11
Configuring the mls ip ids Command, page 15-14
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0

Configuring the Catalyst Series 6500 Switch for IDSM-2 in Promiscuous Mode

3-2.
15-7

Advertisement

Table of Contents
loading

Table of Contents