hit counter script

Command And Control Interface - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Chapter 1
Introducing the Sensor
ports are numbered from top to bottom). Interfaces with a given slot are numbered beginning with port
0 for the right port with the port numbers increasing from right to left. For example, GigabitEthernet2/1
supports a maximum speed of 1 Gigabit and is the second-from-the-right interface in the
second-from-the bottom PCI expansion slot. The IPS 4240, IPS 4255, IPS 4260, and IPS 4270-20 are
exceptions to this rule. The command and control interface on these sensors is called Management0/0
rather than GigabitEthernet0/0. The IPS 4270-20 has an additional interface called Management0/1,
which is reserved for future use.
There are three interface roles:
There are restrictions on which roles you can assign to specific interfaces and some interfaces have
multiple roles. You can configure any sensing interface to any other sensing interface as its TCP reset
interface. The TCP reset interface can also serve as an IDS (promiscuous) sensing interface at the same
time. The following restrictions apply:

Command and Control Interface

The command and control interface has an IP address and is used for configuring the sensor. It receives
security and status events from the sensor and queries the sensor for statistics.
The command and control interface is permanently enabled. It is permanently mapped to a specific
physical interface, which depends on the specific model of sensor. You cannot use the command and
control interface as either a sensing or alternate TCP reset interface.
Table 1-1
Table 1-1
Sensor
AIM IPS
AIP SSM-10
AIP SSM-20
AIP SSM-40
IDSM2
IPS 4240
OL-18504-01
Command and control
Sensing
Alternate TCP reset
Because the AIM IPS, AIP SSM, and NME IPS only have one sensing interface, you cannot
configure a TCP reset interface.
Because of hardware limitations on the Catalyst switch, both of the IDSM2 sensing interfaces are
permanently configured to use System0/1 as the TCP reset interface.
The TCP reset interface that is assigned to a sensing interface has no effect in inline interface or
inline VLAN pair mode, because TCP resets are always sent on the sensing interfaces in those
modes.
Each physical interface can be divided into VLAN group subinterfaces, each of which
Note
consists of a group of VLANs on that interface.
lists the command and control interfaces for each sensor.
Command and Control Interfaces
Command and Control Interface
Management0/0
GigabitEthernet0/0
GigabitEthernet0/0
GigabitEthernet0/0
GigabitEthernet0/2
Management0/0
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
How the Sensor Functions
1-5

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents