Verifying The Sensor Is Synchronized With The Ntp Server; Tcp Reset Not Occurring For A Signature - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix C
Troubleshooting
The syslog is much slower than logApp (about 50 messages per second as opposed to 1000 or so). We
Caution
recommend that you enable debug severity on one zone at a time.

Verifying the Sensor is Synchronized with the NTP Server

In IPS 5.0, you cannot apply an incorrect NTP configuration, such as an invalid NTP key value or ID, to
the sensor. If you try to apply an incorrect configuration, you receive an error message. To verify the
NTP configuration, use the show statistics host command to gather sensor statistics. The NTP statistics
section provides NTP statistics including feedback on sensor synchronization with the NTP server.
To verify the NTP configuration, follow these steps:
Log in to the sensor.
Step 1
Generate the host statistics:
Step 2
sensor# show statistics host
Generate the hosts statistics again after a few minutes:
Step 3
sensor# show statistics host
Step 4
If the status continues to read
the NTP server is configured correctly.

TCP Reset Not Occurring for a Signature

If you do not have the event action set to reset, the TCP reset does not occur for a specific signature.
To troubleshoot a reset not occurring for a specific signature, follow these steps:
Log in to the CLI.
Step 1
Make sure the event action is set to TCP reset:
Step 2
sensor# configure terminal
78-16527-01
...
NTP Statistics
remote
11.22.33.44
CHU_AUDIO(1)
LOCAL(0)
73.78.73.84
ind assID status
conf reach auth condition
1 10372
f014
yes
2 10373
9014
yes
status = Not Synchronized
...
...
NTP Statistics
remote
*11.22.33.44
CHU_AUDIO(1)
LOCAL(0)
73.78.73.84
ind assID status
conf reach auth condition
1 10372
f624
yes
2 10373
9024
yes
status = Synchronized
Not Synchronized
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
refid
st t when poll reach
8 u
36
5 l
35
yes
ok
reject
yes
none
reject
refid
st t when poll reach
8 u
22
5 l
22
yes
ok
sys.peer
yes
none
reject
, check with the NTP server administrator to make sure
Troubleshooting the 4200 Series Appliance
delay
offset
64
1
0.536
0.069
64
1
0.000
0.000
last_event cnt
reachable
1
reachable
1
delay
offset
64
377
0.518
37.975
64
377
0.000
0.000
last_event cnt
reachable
2
reachable
2
jitter
0.001
0.001
jitter
33.465
0.001
C-29

Advertisement

Table of Contents
loading

Table of Contents