Configuring The Catalyst Series 6500 Switch For Idsm-2 In Inline Mode - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring the Catalyst Series 6500 Switch for IDSM-2 in Inline Mode

You can use the mls ip ids command to designate which packets will be captured. Packets that are
permitted by the ACL will be captured. Those denied by the ACL will not be captured. The permit/deny
parameter does not affect whether a packet is forwarded to destination ports. Packets coming into that
router interface are checked against the IPS ACL to determine if they should be captured.
To use the mls ip ids command to capture IDS traffic, follow these steps:
Log in to the console.
Step 1
Enter global configuration mode:
Step 2
router# configure terminal
Configure an ACL to designate which packets will be captured:
Step 3
router(config)# ip access-list extended word
Select the interface that carries the packets to be captured:
Step 4
router(config)# interface interface_name
Specify the capture VLANs:
Step 5
router(config)# intrusion-detection module module_number data-port data_port_number
capture allowed-vlan capture_vlans
Example:
router(config)# intrusion-detection module 4 data-port 1 capture allowed-vlan 165
Apply the ACL created in Step 4 to the interface selected in Step 5:
Step 6
router(config-if)# mls ip ids word
Caution
For IDSM-2 to capture all packets marked by the mls ip ids command, data port 1 or data port 2 of
IDSM-2 must be a member of all VLANs to which those packets are routed.
Configuring the Catalyst Series 6500 Switch for IDSM-2 in Inline
Mode
You can use IDM or the CLI to configure the IDSM-2 to operate in inline mode between two separate
VLANs (one VLAN for each side of the IDM-2). To prepare the IDSM-2 for inline mode, you must
configure the switch as well as the IDSM-2. Configure the switch first, then configure the IDSM-2
interfaces for inline mode. For the procedure for configuring IDSM-2 to run in promiscuous or inline
mode, see
This section contains the following topics:
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
15-16
Chapter 5, "Configuring Interfaces."
Catalyst Software, page 15-17
Cisco IOS Software, page 15-18
Chapter 15
Configuring IDSM-2
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents