Verifying and Testing CBAC


Like other Cisco router features, CBAC services let you display various parameters using show commands. You can also debug CBAC services using debugging commands, and you can reset CBAC parameters using a no command.

Show Commands

The show commands to display CBAC parameters are clear-cut .

A very useful CBAC command is show ip inspect all , which you use to display all available CBAC information and to display CBAC active session inspection information.

You use the show ip inspect config command to display parameters that you have configured along with default CBAC parameters.

Use the show ip inspect interface command to display the interface or interfaces to which you have applied your CBAC policies.

Use the show ip inspect sessions [detail] command to display sessions that are currently being inspected and tracked by CBAC. The detail keyword displays more information about the sessions.

Debug Commands

Debugging can be helpful when you need to troubleshoot your CBAC configurations. Cisco has a number of debug commands available for use with CBAC. Some of the more important IDS debug commands follow:

 
 debug ip inspect  protocol  Use any of the supported protocols or applications with the debug ip inspect  protocol  command: debug ip inspect detailed debug ip inspect events debug ip inspect object-creation debug ip inspect object-deletion debug ip inspect timers 


CCSP SECUR Exam Cram 2
CCSP SECUR Exam Cram 2 (642-501)
ISBN: B000MU86IQ
EAN: N/A
Year: 2003
Pages: 291
Authors: Raman Sud

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net