Summary Of Ips 5.0 Applications - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix A
System Architecture

Summary of IPS 5.0 Applications

Table A-2
Table A-2
Application
AuthenticationApp
CLI
Event Server
MainApp
InterfaceApp
LogApp
Network Access Controller
NotificationApp
SensorApp
Control Transaction Server
Control Transaction Source
78-16527-01
/usr/cids/idsRoot/lib—Contains the library files for the sensor applications.
/usr/cids/idsRoot/log—Contains the log files for debugging.
/usr/cids/idsRoot/tmp—Stores the temporary files created during run time of the sensor.
gives a summary of the applications that make up the IPS.
Summary of Applications
1
2
3
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Description
Authorizes and authenticates users based on IP address, password,
and digital certificates.
Accepts command line input and modifies the local configuration
using IDAPI.
Accepts RDEP2 request for events from remote clients.
Reads the configuration and starts applications, handles starting and
stopping of applications and node reboots, handles software
upgrades.
Handles bypass and physical settings and defines paired interfaces.
Physical settings are speed, duplex, and administrative state.
Writes all the application's log messages to the log file and the
application's error messages to the Event Store.
A Network Access Controller is run on every sensor. Each Network
Access Controller subscribes to network access events from its local
Event Store. The Network Access Controller configuration contains
a list of sensors and the network access devices that its local Network
Access Controller controls. If a Network Access Controller is
configured to send network access events to a master blocking sensor,
it initiates a network access control transaction to the remote
Network Access Controller that controls the device. These network
access action control transactions are also used by IPS managers to
issue occasional network access actions.
Sends SNMP traps when triggered by alert, status, and error events.
NotificationApp uses the public domain SNMP agent. SNMP GETs
provide information about the general health of the sensor.
Captures and analyzes traffic on the monitored network and generates
intrusion and network access events. Responds to IP logging control
transactions that turn logging on and off and that send and delete IP
log files.
Accepts control transactions from a remote RDEP2 client, initiates a
local control transaction, and returns the response to the remote
client.
Waits for control transactions directed to remote applications,
forwards the control transactions to the remote node using RDEP2,
and returns the response to the initiator.
Summary of IPS 5.0 Applications
A-37

Advertisement

Table of Contents
loading

Table of Contents