Unable To See Alerts - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix C
Troubleshooting
If the Link Status is down, make sure the sensing port is connected properly:
Step 3
a.
b.
Verify the interface configuration:
Step 4
a.
b.
Verify again that the interfaces are up and that the packet count is increasing.
Step 5
sensor# show interfaces

Unable to See Alerts

If you are not seeing alerts, try the following:
To make sure you can see alerts, follow these steps:
Log in to the CLI.
Step 1
Make sure the signature is enabled:
Step 2
sensor# configure terminal
sensor(config)# service signature-definition sig0
sensor(config-sig)# signatures 1300 0
sensor(config-sig-sig)# status
sensor(config-sig-sig-sta)# show settings
status
-----------------------------------------------
-----------------------------------------------
78-16527-01
Make sure the sensing port is connected properly on the appliance.
See the chapter on your appliance in Installing Cisco Intrusion Prevention System Appliances and
Modules 5.0.
Make sure the sensing port is connected to the correct SPAN or VACL capture port on IDSM-2.
For the procedures, see
Chapter 15, "Configuring IDSM-2."
Make sure you have the interfaces configured properly.
For the procedure see
Chapter 5, "Configuring Interfaces."
Verify the SPAN and VACL capture port configuration on the Cisco switch.
Refer to your switch documentation for the procedure.
Make sure the signature is enabled.
Make sure the signature is not retired.
Make sure that you have Produce Alert configured as an action.
If you choose Produce Alert, but come back later and add another event action and do not
Note
add Produce Alert to the new configuration, alerts are not be sent to the Event Store. Every
time you configure a signature, the new configuration overwrites the old one, so make sure
you have configured all the event actions you want for each signature.
Make sure the sensor is seeing packets.
Make sure that alerts are being generated.
enabled: true <defaulted>
retired: false <defaulted>
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Troubleshooting the 4200 Series Appliance
C-11

Advertisement

Table of Contents
loading

Table of Contents