cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
559
Views
0
Helpful
2
Replies

CHIDS Connection problems

ktimm
Level 1
Level 1

I can't get an agent to show up in the IDS console.

The agent local to the console shows up fine. Running tcpdump there appears to be normal traffic to port 5000 (syn, syn-ack, ack , ack-push,fin ). I thought this was supposed to be encrypted ? Do I possibly have a problems with the key ? The key was copied from console to a follpy and then off the floopy to the agent so it should be OK. Any suggestions ?

2 Replies 2

giovanni
Level 1
Level 1

It's probably a key problem.

Rather than copying the key from the console get it from a working agent. It is possible to have a wrong publickey file in the console's directory, since the console itself doesn't use it, it only uses the privatekey file.

If this doesn't work, enable the debug mode on the agent and send the content of the cslog.txt file which is created.

Ciao,

Giovanni

kleem
Cisco Employee
Cisco Employee

If you are copying the key from the host that you installed the console on, make sure you grab the key from agent directory. You will have to reboot after you install the key.