CSIDS Exam Cram 2 (Exam 642-531)
Authors: Newman D.P. Manalo K.M.
Published year: 2004
Pages: 11-13/213
Buy this book on amazon.com >>
[ LiB ]  

CISCO IDS NAVIGATION

  1. You can access the command-line interface (CLI) by using the console port, Telnet and SSH to the command and control interface, or a direct monitor and keyboard ports on most models. However, the IDS-4215 does not have monitor and keyboard ports.

  2. The IDS 4.0 supports SSH versions 1 and 2 protocols.

  3. CLI locations:

    Syntax

    Location

    Sensor#

    Privilege exec

    Sensor(config)#

    Global configuration

    Sensor(config-if)#

    Command and control interface

    Sensor(config-ifs)#

    Sensing interface

    Sensor(config-ifg)#

    Interface group

    Sensor(config-Host-net)#

    NetworkParams configuration


  4. The NetworkParams configures several sensor networking settings, such as IP address, default gateway, hostname, and access list.

  5. The interface command-control mode enables you to configure an IP address for the sensor.

  6. The NetworkAccess service allows the configuration of managed devices; it has the prompt sensor(config-NetworkAccess)# .

  7. Configuring a managed device:

    • Set the VTY line password (Telnet).

    • Set the enable password. (Make it the same as the VTY line.)

    • Enable Telnet on the device.

    • Add the sensor to the trusted host list on the device.

  8. WebServer Service that allows the configuration of the HTTP/HTTPS cidwebServer application. The command prompt is sensor(config-WebServer)# .

  9. Virtual-sensor-configuration Level that allows you to fine-tune signature settings or even create custom signatures. The command prompt is sensor(config-vsc)# .

    • All signature tuning and custom signatures created are linked to this virtualSensor group.

    • To reset String.TCP settings back to default, use sensor(config-vsc)# reset-signature STRING.TCP all at the virtual-sensor-configuration level.

[ LiB ]  
[ LiB ]  

COMMANDS

  1. Use the ssh authorized-key command to add a public key for the current user for a client allowed to use Rivest Shamir Adleman (RSA) authentication to log in to the local SSH server.

  2. The copy /erase backup-config current-config command first erases the destination file before copying the backup-config to the current-config.

  3. The sensor has two partitions. The recover command re-images the application partition with the image stored on the recovery partition. An example is Sensor(config)#recover application-partition .

  4. The recover application partition command is not supported on the IDSM2 switch module.

  5. Two methods for updating a sensor are using the sensor(config)# upgrade command or using IDS MC. The command supports four source locations: FTP, Secure Copy Protocol (SCP), HTTP, or HTTPS.

  6. You can use the sensor(config)# downgrade command to remove the latest update.

  7. You must upgrade IDS MC prior to upgrading the sensor with service packs or signature updates.

  8. The update filename IDS-K9-sp-4.0-2-S42.rpm.pkg has a service pack level of 2, an IDS major release 4.0, and signature level 42.

  9. For SSH, the sensor and blocking device must exchange keys manually using the ssh host-key command. Also, Data Encryption Standard (DES) or Triple DES (3DES) must be available.

[ LiB ]  
[ LiB ]  

IEV AND IDM

  1. IDM requires Netscape 4.79 or Internet Explorer 5.5 with Service Pack 2 (SP2) or higher as client browsers.

  2. The Network Security Database (NSDB) provides detailed signature and vulnerability information and is a component of IEV.

  3. IEV custom view allows you to use filters to select what traffic you want to view and to adjust the order in which the columns appear by using the up and down arrow buttons .

  4. You can import archived IDS log files from the sensor into IEV.

  5. The events displayed in the Statistical Graph reflect the average number of alarms received by IEV, based on the filter that is applied to the data source. Therefore, depending on the filter, the Statistical Graph might not reflect the true average number of alarms.

[ LiB ]  
CSIDS Exam Cram 2 (Exam 642-531)
Authors: Newman D.P. Manalo K.M.
Published year: 2004
Pages: 11-13/213
Buy this book on amazon.com >>