asa - Configuring the Cisco Intrusion Prevention System Using the Command Line Interface 6.0.pdf
(
11367 KB
)
Pobierz
S E C R E TA R I AT R E V I E W — C I S C O C O N F I D E N T I A L
Configuring the Cisco Intrusion Prevention
System Using the Command Line Interface
6.0
Americas Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 527-0883
Customer Order Number:
Text Part Number: OL-8826-01
S E C R E TA R I AT R E V I E W — C I S C O C O N F I D E N T I A L
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL
STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT
WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT
SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE
OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB’s public
domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH
ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT
LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF
DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING,
WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
CCDE, CCENT, Cisco Eos, Cisco Lumin, Cisco StadiumVision, the Cisco logo, DCE, and Welcome to the Human Network are trademarks; Changing the Way We Work,
Live, Play, and Learn is a service mark; and Access Registrar, Aironet, AsyncOS, Bringing the Meeting To You, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, CCSP,
CCVP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity,
Collaboration Without Limitation, EtherFast, EtherSwitch, Event Center, Fast Step, Follow Me Browsing, FormShare, GigaDrive, HomeLink, Internet Quotient, IOS, iPhone,
iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, iQuick Study, IronPort, the IronPort logo, LightStream, Linksys, MediaTone, MeetingPlace, MGX, Networkers,
Networking Academy, Network Registrar, PCNow, PIX, PowerPanels, ProConnect, ScriptShare, SenderBase, SMARTnet, Spectrum Expert, StackWise, The Fastest Way to
Increase Your Internet Quotient, TransPath, WebEx, and the WebEx logo are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain
other countries.
All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship
between Cisco and any other company. (0804R)
Any Internet Protocol (IP) addresses used in this document are not intended to be actual addresses. Any examples, command display output, and figures included in the
document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental.
Configuring the Cisco Intrusion Prevention System Using the Command Line Interface 6.0
© 2006-2008 Cisco Systems, Inc. All rights reserved.
S E C R E TA R I AT R E V I E W — C I S C O C O N F I D E N T I A L
CONTENTS
Preface
i-xxiii
i-xxiii
i-xxiii
i-xxiv
i-xxiv
Audience
Conventions
Related Documentation
Obtaining Documentation, Obtaining Support, and Security Guidelines
1
CHAPTER
Introducing the CLI Configuration Guide
Overview
User Roles
CLI Behavior
1-1
1-1
1-1
Sensor Configuration Task Flow
1-3
1-4
1-6
1-7
1-8
Command Line Editing
IPS Command Modes
General CLI Commands
CLI Keywords
2
1-10
Regular Expression Syntax
1-10
CHAPTER
Logging In to the Sensor
Overview
2-1
2-1
Supported User Roles
2-1
2-2
2-3
Logging In to the Appliance
Connecting an Appliance to a Terminal Server
Directing Output to a Serial Connection
Logging In to IDSM-2
Logging In to NM-CIDS
2-5
2-6
2-4
Logging In to AIM-IPS
2-7
Overview
2-7
Sessioning In to AIM-IPS
Logging In to AIP-SSM
Logging In to the Sensor
2-10
2-11
2-8
Configuring the Cisco Intrusion Prevention System Using the Command Line Interface 6.0
OL-8826-01
iii
Contents
S E C R E TA R I AT R E V I E W — C I S C O C O N F I D E N T I A L
CHAPTER
3
Initializing the Sensor
Overview
3-1
3-1
System Configuration Dialog
3-1
Initializing the Sensor
3-3
Initializing the Appliance
3-3
Initializing IDSM-2
3-12
Initializing AIM-IPS
3-19
Initializing AIP-SSM
3-24
Initializing NM-CIDS
3-31
Verifying Initialization
3-36
4
CHAPTER
Initial Configuration Tasks
4-1
Changing Network Settings
4-1
Changing the Hostname
4-2
Changing the IP Address, Netmask, and Gateway
Enabling and Disabling Telnet
4-4
Changing the Access List
4-5
Changing the FTP Timeout
4-7
Adding a Login Banner
4-8
Changing Web Server Settings
4-9
4-3
Configuring User Parameters
4-11
Adding and Removing Users
4-11
Password Recovery
4-13
Understanding Password Recovery
4-13
Password Recovery for Appliances
4-14
Password Recovery for IDSM-2
4-15
Password Recovery for NM-CIDS
4-16
Password Recovery for AIP-SSM
4-17
Password Recovery for AIM-IPS
4-17
Disabling Password Recovery
4-18
Verifying the State of Password Recovery
4-18
Troubleshooting Password Recovery
4-19
Creating the Service Account
4-19
Configuring Passwords
4-21
Changing User Privilege Levels
4-21
Viewing User Status
4-22
Configuring Account Locking
4-23
Configuring Time
4-24
Time Sources and the Sensor
4-24
Configuring the Cisco Intrusion Prevention System Using the Command Line Interface 6.0
iv
OL-8826-01
Contents
S E C R E TA R I AT R E V I E W — C I S C O C O N F I D E N T I A L
Synchronizing IPS Module System Clocks with the Parent Device System Clock
Correcting Time on the Sensor
4-27
Configuring Time on the Sensor
4-28
System Clock
4-28
Configuring Summertime Settings
4-29
Configuring Timezones Settings
4-33
Configuring NTP
4-34
Configuring a Cisco Router to be an NTP Server
4-34
Configuring the Sensor to Use an NTP Time Source
4-36
Configuring SSH
4-37
Understanding SSH
4-37
Adding Hosts to the SSH Known Hosts List
Adding SSH Authorized Public Keys
4-39
Generating a New SSH Server Key
4-41
4-27
4-38
Configuring TLS
4-41
Understanding TLS
4-41
Adding TLS Trusted Hosts
4-42
Displaying and Generating the Server Certificate
Installing the License Key
4-44
Overview
4-45
Service Programs for IPS Products
4-45
Obtaining and Installing the License Key
4-47
5
4-44
CHAPTER
Configuring Interfaces
5-1
Understanding Interfaces
5-1
Command and Control Interface
5-2
Sensing Interfaces
5-3
TCP Reset Interfaces
5-3
Understanding Alternate TCP Reset Interfaces
5-3
Designating the Alternate TCP Reset Interface
5-4
Interface Support
5-5
Hardware Bypass Mode
5-8
Hardware Bypass Card
5-8
Hardware Bypass Configuration Restrictions
5-9
Interface Configuration Restrictions
5-10
Configuration Sequence
5-12
Configuring Physical Interfaces
5-12
Promiscuous Mode
5-15
Understanding Promiscuous Mode
5-15
Configuring the Cisco Intrusion Prevention System Using the Command Line Interface 6.0
OL-8826-01
v
Plik z chomika:
lennyx
Inne pliki z tego folderu:
asa - Cisco Security Appliance Command Line Configuration Guide.pdf
(17698 KB)
asa - Configuring the Cisco Intrusion Prevention System Using the Command Line Interface 6.0.pdf
(11367 KB)
ASA.PIX.and.FWSM.Handbook.2nd.Edition.Aug.2007.eBook-DDU.pdf
(8979 KB)
Cisco AS5x00 Case Study for Basic IP Modem Services - AS5x00.pdf
(1686 KB)
cisco.press.asa.and.pix.firewall.handbook.chm
(20913 KB)
Inne foldery tego chomika:
acs
bcmsn
bgp
ccie
design
Zgłoś jeśli
naruszono regulamin