cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
599
Views
0
Helpful
3
Replies

manual blocking using IDS

teru-lei
Level 1
Level 1

Hi All,

I tried to use IDS to block traffic. I have configured the logical device and add the blocking router with all passwords, but after I configured the blocking, the IDS did not apply acl to the router... Just don't know which step is wrong.

And I can not find somewhere in IDS to monitor which equipment has applied the blocking... Can anybody give me some ideas? Thank You!

Best Regards

Teru Lei

3 Replies 3

jlively
Cisco Employee
Cisco Employee

How did you configure the sensor? Did you use the cli? If so, do a show statistics network-access. You will see the current status of the connection and any active blocks. Look for the word "active" for the router. You said you set up the logical device and the router. Did you also set up and interface on the router?

Thank you! I use GUI to config the IDS. I will check my config again

go to the monitoring tab and make sure the blocks are listed. Go to the blocking config and router interfaces. Still a good bet to go to the cli and check stats there.

Review Cisco Networking for a $25 gift card