03-23-2001 02:12 AM - edited 03-08-2019 08:05 PM
I am yet to play with Cisco Secure IDS, but need a couple of answers if anyone is willing ;-)
How does a probe find alternate routes to the director??
Is it based on normal routing via a gateway?
If contact is lost to the director does the probe continue to log to a local store?
03-23-2001 07:44 AM
I'm not sure I understand the first question...normal communications are established using "normal routing" via a default gateway from the sensor. The sensor(probe) can be configured to report to multiple directors if you want redundancy, but it still has one network connection. [the sensor has one network interface for the monitored network and one network interface for command & control. Our standard recommendation is to run C&C on a network separate from the monitored network eg. out of band]
As for the lost contact question, the answer is yes. Alarms will be logged on the local system until contact is re-established, at which time they will be forwarded to the director.
03-26-2001 05:51 AM
Excellent response, just exactly what I wanted to know.
Thanx again
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide