cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1486
Views
4
Helpful
6
Replies

"ip audit" command not found

nocsertech
Level 1
Level 1

Hi expert

I would like to configure IDS on my C7200 NPE-G1 to monitor my out bound traffic of my WS-C6504.

I tried to follow instruction here "IDS instruction". I am unable to apply the first command below. There are no such command. Is there anything I need to enable prior to this?

Thank you in advance for your help.

Router(config)#ip audit?
% Unrecognized command
Router(config)#ip audit

Router(config)#ip audit notify log
                               ^
% Invalid input detected at '^' marker.

1 Accepted Solution

Accepted Solutions

The implementation of IPS changed many times in the past. If your IOS is not really ancient, it's likely that the command is "ip ips ..." on your router.

View solution in original post

6 Replies 6

The implementation of IPS changed many times in the past. If your IOS is not really ancient, it's likely that the command is "ip ips ..." on your router.

Thank you for taking time to reply. I wish to use IDS instead of IPS. My goal is to have alert on suspicious traffic instead of blocking them. The reason is to avoid false positive and blocked good traffic.

I am considering using NPE-G1 or IDSM-2. My traffic to WAN is about 100mbps. 

It's the syntax that changed over time. You still have the possibility to operate in IDS or IPS mode. IDSM-2 is completely outdated. You should look at FirePower for up-to-date IPS/IDS.

Noted the mode setting. Thank you for the valuable info.

Noted your recommendation of FirePower.

The intention is to have better monitoring on suspicious traffic especially for smtp spamming out from our network. Once alerted, we will investigate manually. Since we have 2 units of C7206 NPE-G1 in store sleeping do nothing, I planned to use them for IDS purpose.   

Also think about sending NetFlow data to a netflow collector. That will also show you when the behavior of your network changes. Probably it will give you more useful information than IDS in that case.

Thank you. Will study NetFlow to understand more.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card